[Openstack-security] [Bug 1583788] [NEW] Security role should use pam_faillock for V-38501 on CentOS

Major Hayden major at mhtx.net
Thu May 19 20:48:31 UTC 2016


Public bug reported:

Ubuntu doesn't package pam_faillock, so fail2ban was used to satisfy the
requirements in V-38501. CentOS 7 has pam_faillock and it should be used
on CentOS 7 to more closely align with the STIG's requirements.

** Affects: openstack-ansible
     Importance: Wishlist
     Assignee: Major Hayden (rackerhacker)
         Status: New


** Tags: security

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1583788

Title:
  Security role should use pam_faillock for V-38501 on CentOS

Status in openstack-ansible:
  New

Bug description:
  Ubuntu doesn't package pam_faillock, so fail2ban was used to satisfy
  the requirements in V-38501. CentOS 7 has pam_faillock and it should
  be used on CentOS 7 to more closely align with the STIG's
  requirements.

To manage notifications about this bug go to:
https://bugs.launchpad.net/openstack-ansible/+bug/1583788/+subscriptions




More information about the Openstack-security mailing list