Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
emilli_xill
Participant

Password policy settings in a text file

Hello everyone!

I need to control password policies via another application. This app can read text file and compare it with "ideal configuration". So, I need to know in which files I can find information about such policies (GAIA OS and Smart Console). 

For example, I need to know if "The account will be blocked after ??? unsuccessful attempts" or "You need to change the password every ??? days" or files describing settings from GaiaPortal - User management - Password policy..

I know I can find some information in "shadow" file, but there is not enough information there..

I'm not looking for a way to find a file with unencripted passwords! - I'm looking for text files that describe password policies.

Also I need to see audit log files (for example, all actions performed under expert-shell or login attempts). I found audit logs in $FWDIR/log, but they are encripted. 

So could you please explain how can I do this, or maybe all this information will be encripted for security reasons and I won't be able to access it in a readable form?

Thank you!

0 Kudos
5 Replies
_Val_
Admin
Admin

Passwords are never stored as cleartext, so you cannot verify them by looking at the text tive.

You may want to specify the use case and the desired outcome in some better terms, if you want answers.

0 Kudos
emilli_xill
Participant

Of course, I understand about passwords.. 😱 I'm looking for information about password policies, not passwords themselves. Text files which describe what requirements apply to passwords, how often to change them, what to do if there are many login attemps etc. 

Sorry, English is not my native language and sometimes it is hard to say in a way that is clear 😞

0 Kudos
Alex-
Leader Leader
Leader

Shell access is logged into /var/log/messages so you could syslog them.

In expert, you could run clish -c "show password-controls all" to get the current status of the appliance and send this to a file for further processing.

G_W_Albrecht
Legend Legend
Legend

And Audit logs can be found in Legacy SmartView Tracker, Management Tab. With File > Export... they will be saved as .txt.

 

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
_Val_
Admin
Admin

I see you already get an answer that you consider useful. I just want to elaborate on that.

To see the password policy settings on Gaia, you need to query it from the config. See the admin guide for more details: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Gaia_AdminGuide/Content/Topi...

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events