cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
138
Views
0
Helpful
3
Replies

CUCM - PAM (Pluggable Authentication Modules) and SSHD (Secure Shell)

Quintin.Mayo
Level 3
Level 3

Hi,

We have received alerts that PAM (Pluggable Authentication Modules) and SSHD (Secure Shell Daemon) are disagreeing on the maximum number of password retry attempts allowed for a user.  From my research conducted the sshd_config file
'MaxAuthTries" parameter will have to be modified, and the PAM pam_tally or pam_unix file " retry settings".  But this procedure is not recommended and needs root access.  Can anyone confirm this and recommend an alternative workaround.  It would be greatly appreciated.

 

Thanks,

 

 

3 Replies 3

From where are you getting this alert?



Response Signature


Hi,

We are receiving the below alert via SNMP for the publisher.

LME57260171 critical - XXXX.XXXX.local CUCM Syslog
Host: XXXX.XXXX.local
Service.Level: proactive
Description:
Device Criticality: 1
Eventsource: CUCM Syslog
Message: sshd: PAM service(sshd) ignoring max retries; 6 > 3

 

This smells like a TAC case miles away. I’ve never seen or heard of that type of alert.



Response Signature