On 06/07/2010 15:11, Piotr Jasiukajtis wrote:
I should add that I use pam_krb5 module already, so in that case
'lock_after_retries' should be implemented within KDC or on the LDAP
level?

Sure having the KDC do it if you are using Kerberos is another good choice.

--
Darren J Moffat
_______________________________________________
security-discuss mailing list
[email protected]

Reply via email to