Bug ID 1778721: PAM faillock data is deleted on restart, allowing users to log in immediately

Last Modified: Oct 19, 2025

Affected Product(s):
F5OS Velos(all modules)

Known Affected Versions:
F5OS-A 1.5.2, F5OS-A 1.5.3, F5OS-A 1.5.4, F5OS-A 1.8.0, F5OS-A 1.8.3, F5OS-C 1.6.0, F5OS-C 1.6.1, F5OS-C 1.6.2, F5OS-C 1.6.4, F5OS-C 1.8.0, F5OS-C 1.8.1, F5OS-C 1.8.2

Opened: Dec 18, 2024

Severity: 3-Major

Symptoms

The administrator can set up the max-login-failures (Number of unsuccessful login attempts allowed before lockout) to a non-zero number. Also, the unlock-timeout can be increased from the default value of 60 seconds. Once the number of failed login attempts is reached, then the user must wait the alotted unlock-timeout period before being allowed to login with the correct credentials. The number of login-failures for each user is currently reset to zero upon a system reboot.

Impact

The max-login-failures setting is set back to zero if the system is rebooted.

Conditions

Rebooting simply eliminates the tally count of login failures for all users.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips