UNIX login attempt restriction

: If a enter a invalid login name and password, the system continuously asks
: for my username.

: I'm logging in via a modem to a Motorola host running System 5 Rel 3 using ksh.

: I know on other systems you get 3 chances and then your forced out.

: How can I get the host to force me out after 3 attempts ?

Motorola, OK, but which UN*X version? (Almost) modern UN*X computers
have a "login" binary (/etc/login, that is) that will allow configuration
to some extent. On my system (SGI IRIX 5.3) the file /etc/defaults/login
can have a field MAXTRYS (=3 by default) to set this.

So.... man "login"


1. Root login restrictions, without complete su restriction?

I'm trying to help a client beef up the previously lax security on their
AIX 4.1.4 system, and what I'd like to be able to do is something that
other UNIX operating systems allow, and I'm just having a bit of trouble
figuring out how to implement it on AIX.

I'd like to restrict anyone from logging in directly as "root" on all
terminals except for the console, but allow users in the "system" group
to "su" to root.  I've got this working with "rlogin" and "telnet" by
disallowing remote logins in root's security characteristics, but as
far as I've been able to figure out so far, restricting the terminals
is essentially an all-or-nothing proposition.

If I restrict root to "/dev/tty0", the console, not only can I not log
in as root anywhere else, but I also can't "su" to root, even though
I'm in the system group.

Is there some way to prevent a direct login as root, but still allow
"su" by authorized users?  Is there some concept of an "unsecure"

