Re: Request for comments regarding default configuration of pam_abl module

2014-03-24 Thread Christopher Meng
Is there a policy that for different Fedora.next products, we can apply different rules? Or just add comments in the conf? -- devel mailing list devel@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/devel Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct

Re: Request for comments regarding default configuration of pam_abl module

2014-03-24 Thread Corey Sheldon
My personal take is for desktop (normal end-user) that it stays as is or as a option in an advanced options setting and in the server-land to make the added DoS environment default as any of us in that realm should know not only about to determine our environment's needs but how to adjust Corey W

Re: Request for comments regarding default configuration of pam_abl module

2014-03-24 Thread Kevin Fenzi
On Sun, 23 Mar 2014 23:46:15 -0600 Eric Smith wrote: > In bug #1079767, it is requested that the default configuration for > pam_abl be changed such that multiple root login failures from a > network host will (temporarily) blacklist that host. The existing > default configuration deliberately d

Request for comments regarding default configuration of pam_abl module

2014-03-23 Thread Eric Smith
In bug #1079767, it is requested that the default configuration for pam_abl be changed such that multiple root login failures from a network host will (temporarily) blacklist that host. The existing default configuration deliberately does not do that, due to potential for a Denial of Service. For