Q: After a security audit, you need to enforce password complexity and account lockout policies across all Linux servers. What mechanism controls this, and how do you configure it?
Linux uses PAM (Pluggable Authentication Modules) for authentication policy enforcement. PAM configuration files are located in /etc/pam....
#Linux #Linux / SRE — Scenario-Based Interview Questions #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""We encountered this OS-level bottleneck during peak traffic and diagnosed it down to kernel and filesystem metrics. The interviewer is testing: PAM (Pluggable Authentication Modules), security hardening.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Linux uses PAM (Pluggable Authentication Modules) for authentication policy enforcement. PAM configuration files are located in /etc/pam.d/ and control how authentication, password changes, and session management behave.
- Password Complexity: Edit
/etc/pam.d/common-password(Debian) or/etc/pam.d/system-auth(RHEL) and add: - Account Lockout: Add to
/etc/pam.d/common-auth: - Password History: Prevent password reuse:
2️⃣
Remediation & Permanent Safeguards
Key configurations: This enforces minimum 12 characters with at least 1 digit, 1 uppercase, 1 lowercase, and 1 special character. This locks the account for 15 minutes after 5 failed login attempts.
password requisite pam_pwquality.so retry=3 minlen=12 dcredit=-1 ucredit=-1 ocredit=-1 lcredit=-1
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Password Complexity: Edit /etc/pam.d/common-password (Debian) or /etc/pam.d/system-auth (RHEL) and add:."
⚡ 60-Second Elevator Pitch Talking Points
- Password Complexity: Edit /etc/pam.d/common-password (Debian) or /etc/pam.d/system-auth (RHEL) an...
- Account Lockout: Add to /etc/pam.d/common-auth:
- Password History: Prevent password reuse:
Advertisement