{"id":320,"date":"2020-01-25T11:59:18","date_gmt":"2020-01-25T10:59:18","guid":{"rendered":"http:\/\/blog.mhasin.eu\/?p=320"},"modified":"2020-01-25T19:27:35","modified_gmt":"2020-01-25T18:27:35","slug":"esxi-6-7-restart-zablokovaneho-root-uctu-praca-s-uzivatelmi","status":"publish","type":"post","link":"https:\/\/blog.mhasin.eu\/?p=320","title":{"rendered":"ESXi 6.7 re\u0161tart zablokovan\u00e9ho root \u00fa\u010dtu pr\u00e1ca s u\u017e\u00edvate\u013emi"},"content":{"rendered":"\n<p>Pri zablokovan\u00ed root \u00fa\u010dtu je potrebne na ESXi aktivova\u0165 shell a n\u00e1sledne pomocou pr\u00edkazov vy\u010disti\u0165 po\u010d\u00edtadlo neplatn\u00fdch prihl\u00e1sen\u00ed<\/p>\n\n\n\n<p>Zobrazenie poctu ne\u00faspe\u0161n\u00fdch prihl\u00e1sen\u00ed root \u00fa\u010dtu do ESXi prostredia:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>pam_tally2 --user root<\/code><\/pre>\n\n\n\n<p>Odomknutie zablokovan\u00e9ho \u00fa\u010dtu:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>pam_tally2 --user root --reset<\/code><\/pre>\n\n\n\n<p>Bezpe\u010dnostne politiky v ESXi je mo\u017ene definova\u0165 pre ka\u017ed\u00e9 ESXi zvl\u00e1\u0161\u0165. ESXi 6.x ma preddefinovan\u00e9 bezpe\u010dnostne politiky sily hesla pre u\u017e\u00edvate\u013eov. Politiky pre heslo platne v ESXi 6.x<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Heslo mus\u00ed obsahova\u0165 ve\u013ek\u00e9 p\u00edsmena  ( A-Z ), male p\u00edsmena ( a-z ), \u010d\u00edslice (  0-9 )  pripadne \u0161peci\u00e1lne znaky ( ~!@#$%^&amp;*_-+=`|\\(){}[]:;\u201d\u2018&lt;>,.?\/  )<\/li><li>Heslo mus\u00ed obsahova\u0165 minim\u00e1lne 7 znakov<\/li><li>Ve\u013ek\u00e9 p\u00edsmeno na za\u010diatku sa nepo\u010d\u00edtaj\u00fa do po\u010dtu znakov<\/li><li>\u010c\u00edslica ktor\u00e1 kon\u010d\u00ed v hesle sa nezapo\u010d\u00edtava do poctu znakov <\/li><li>Heslo by nemalo byt prelomiteln\u00e9 slovn\u00edkov\u00fdm \u00fatokom<\/li><\/ul>\n\n\n\n<p>Tieto nastavenia je mo\u017ene zmeni\u0165 v polo\u017eke &#8222;Advanced settings&#8220;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"781\" height=\"199\" src=\"https:\/\/blog.mhasin.eu\/wp-content\/uploads\/2020\/01\/Capture-1.png\" alt=\"\" class=\"wp-image-326\" srcset=\"https:\/\/blog.mhasin.eu\/wp-content\/uploads\/2020\/01\/Capture-1.png 781w, https:\/\/blog.mhasin.eu\/wp-content\/uploads\/2020\/01\/Capture-1-300x76.png 300w, https:\/\/blog.mhasin.eu\/wp-content\/uploads\/2020\/01\/Capture-1-768x196.png 768w\" sizes=\"auto, (max-width: 781px) 100vw, 781px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li> Security.AccountLockFailures  &#8211; Ur\u010duje po\u010det ne\u00faspe\u0161n\u00fdch prihl\u00e1sen\u00ed po ktor\u00fdch d\u00f4jde k zablokovaniu \u00fa\u010dtu.  Zadan\u00edm 0 d\u00f4jde k vypnutiu blokovania \u00fa\u010dtu. (Predvolen\u00e1 hodnota 5)<\/li><li>  Security.AccountUnlockTime  &#8211; Ur\u010duje \u010das po ktorom sa odomkne zablokovan\u00fd \u00fa\u010det. (Predvolen\u00e1 hodnota 900)<\/li><li> Security.PasswordHistory  &#8211; Hist\u00f3ria hesiel zamedzuj\u00faca zmene expirovan\u00e9ho hesla na rovnak\u00e9 povodne heslo.  Vypnutie tejto mo\u017enosti je mo\u017ene zadan\u00edm 0. (Predvolen\u00e1 hodnota 0)<\/li><li> Security.PasswordMaxDays &#8211; Ur\u010duje dl\u00e1\u017eku platnosti hesla. (Predvolen\u00e1 hodnota  99999)<\/li><li> Security.PasswordQualityControl  &#8211; Definuje politiku ur\u010denia sily hesla. (Predvolen\u00e1 hodnota retry=3 min=disabled,disabled,disabled,7,7) <\/li><\/ul>\n\n\n\n<p>Parameter  min=disabled,disabled,disabled,7,7  je rozdelen\u00fd na mo\u017enosti N0-N4:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>N0 &#8211;  Po\u010det znakov ktor\u00fd je potrebn\u00fd ak heslo obsahuje iba jeden druh znakov<\/li><li>N1 &#8211; Po\u010det znakov ktor\u00fd je potrebn\u00fd ak heslo obsahuje dva druhy znakov v hesla (napr\u00edklad ve\u013ek\u00e9 a male p\u00edsmena)<\/li><li>N2 &#8211; Po\u010det znakov ak heslo obsahuje fr\u00e1zu (slovn\u00edkov\u00e9 slovo)<\/li><li>N3 &#8211; Po\u010det znakov ak heslo obsahuje tri druhy znakov (napr\u00edklad ve\u013ek\u00e9 p\u00edsmena, male p\u00edsmena \u010d\u00edsla)<\/li><li>N4 &#8211; Po\u010det znakov ak heslo obsahuje v\u0161etky 4 mo\u017enosti znakov v hesle  (napr\u00edklad ve\u013ek\u00e9 p\u00edsmena, male p\u00edsmena \u010d\u00edsla, \u0161peci\u00e1lne znaky) <\/li><\/ul>\n\n\n\n<p>Konfigur\u00e1ciu je mo\u017ene overi\u0165 v s\u00fabore:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>vi \/etc\/pam.d\/passwd<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"170\" src=\"https:\/\/blog.mhasin.eu\/wp-content\/uploads\/2020\/01\/Password-complexity-settings-view-via-Putty-client-720x170-1.png\" alt=\"\" class=\"wp-image-331\" srcset=\"https:\/\/blog.mhasin.eu\/wp-content\/uploads\/2020\/01\/Password-complexity-settings-view-via-Putty-client-720x170-1.png 720w, https:\/\/blog.mhasin.eu\/wp-content\/uploads\/2020\/01\/Password-complexity-settings-view-via-Putty-client-720x170-1-300x71.png 300w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/figure>\n<div class=\"pdf24Plugin-cp\"> \t<form name=\"pdf24Form0\" method=\"post\" action=\"https:\/\/doc2pdf.pdf24.org\/wordpress.php\" target=\"pdf24PopWin\" onsubmit=\"var pdf24Win = window.open('about:blank', 'pdf24PopWin', 'resizable=yes,scrollbars=yes,width=600,height=250,left='+(screen.width\/2-300)+',top='+(screen.height\/3-125)+''); pdf24Win.focus(); if(typeof pdf24OnCreatePDF === 'function'){void(pdf24OnCreatePDF(this,pdf24Win));}\"> \t\t<input type=\"hidden\" name=\"blogCharset\" value=\"Cw1x07UAAA==\" \/><input type=\"hidden\" name=\"blogPosts\" value=\"MwQA\" \/><input type=\"hidden\" name=\"blogUrl\" value=\"yygpKSi20tdPyslP18vNSCzOzNNLLQUA\" \/><input type=\"hidden\" name=\"blogName\" value=\"c\/LxdwcA\" \/><input type=\"hidden\" name=\"blogValueEncoding\" value=\"gzdeflate base64\" \/><input type=\"hidden\" name=\"postId_0\" value=\"MzYyAAA=\" \/><input type=\"hidden\" name=\"postTitle_0\" value=\"AUMAvP9FU1hpIDYuNyByZcWhdGFydCB6YWJsb2tvdmFuw6lobyByb290IMO6xI10dSBwcsOhY2EgcyB1xb7DrXZhdGXEvm1p\" \/><input type=\"hidden\" name=\"postLink_0\" value=\"yygpKSi20tdPyslP18vNSCzOzNNLLdW3L7A1NjIAAA==\" \/><input type=\"hidden\" name=\"postAuthor_0\" value=\"y00syfcwNAIA\" \/><input type=\"hidden\" name=\"postDateTime_0\" value=\"MzIwMtA1MNQ1MlUwNLQyMLQytAAA\" \/><input type=\"hidden\" name=\"postContent_0\" value=\"tVZLc9s2EL7nV2yZNiO3okjJqRU\/5DZN2slMW9edPKaTPlKIgCVYIMEhQVpkH5MfUN176UGHHHLwqT15xr5Q+iP5JV2A1suyXY819UEmQWC\/bxe7++2dnXB3P+KQk7aQPZmSoDiGSEoFxclooBI4ZBBKFbF2wCAg8PnT7ziQnuIp7h2\/gbjLhAACQTGMBaOB3u1LTyYQRsVxj+QyhTQbDXisOG4P5WhQHCtChYSAhYKooDj1uriZdwWaYAi\/44S7d\/APmb2U7YjkLODarIdsAlacxCEbD5ePLbCmsmQaRjJG8pSTrZnZiIEnSBy3rKPQRre9nu1JyqzdHf1vNyT+K0WEyBpg20nMImN5xzEf0UrEJvS+odLvBYlCenPxe9uV5zRWxcTniMXsUuzPWB6y0SBA\/0zQBVe8l0Fa+o235svxGX6h7IAH5V1pEj0yPqPF23JXnmLwxsPxm1r5vlHrg0\/0Pjo5hu5A+3KomIsMuiwW5gQk47PiOCWKjc5kWoP9yTb9Te+SYK6bTSgi2DQ8iViKjsCMwegIvvvEHPaTGO9YtmPSLb1JEaiH7MLiOPYZpiZU4KH9Etaq6INgs\/UKEDvXyzr1YsE9hkvg2puwBjqDQqLTdjwMmceLocDnPCBIvAK\/v\/fp3fc\/+Oke8cPtD1\/ZH7V+\/vWHytovv33\/49b2u9d\/vXv95z2htnertU8cgLUdB8leQ9jnAfdLgKaBkOn0yItFZ6QutZxg2RDVSyAmuljOS+ewONHprV8x0S\/YGf1Rukigp2RUDKEnA30Mg67vgJWmcjIxlpLSljc1BRfcaGd4AAOqn5S+TCF9rpjQiYHfU6w8PFWc+pjzCivAL887iZhk6jPOlHYoRjgsZTKXnDn6qttCqrMKl3oM7t190Gg0th9SzD2PUcD0VzzoxGbd3Z6mzAHvJJcUFfdJB73kObMFiTq6wLjfASEJRSstS5A8s7AosKDMO4mzwLPgiFPVbVnNB3ULA8U7XdWy6pubFsSR17K6SoXxluMgRKfmd0nMgxpLHAT1ZKBYoJwk1Aix03AbruPWnUckVEjPrtfCoGMBEWjPmiNraNrrjQ2DgD6uDALI\/agKK1ix112339wwxvBxRWPNjQf9+mZpDZ+PLHMp6D1JlKxCxSd920R9SzMP+2tQd90UQc2bBQ7mUHnHN2gR8JR5ScRVVnvoofYE6iv8\/gXhAo\/HYHKqXt+G59FokBhBGw2YulZMQllWkP5Ai38OKbbOuSbPk\/MWXwN4SahWTR\/c2c40C7UuJDA9QKYHKvvYX1MpEGcIXUkDqQh8PGsfsOTN80D7+4z7bNmX0YDEE7bS1\/UtjSotSNKpAWfqCvBN152Dn6LvY7iPZESfYJxllM2w9ULxd4Q+YVPhTCCUz2ieYGvCzqOLmgHrhzya6mEpE9jUcAnbjO50MpW67xppwCi+KCPGQLFDbBemQaDgzEtZPg30FX5c68XXpP+YZPFSAKnWwDPsskaeDKRhewUGbOq\/64C+TQhKX\/YISySSYha1x1pSy\/Qz0phAghRMR5xJ6RWoEVNR1lrXGtKiPMabZbS6\/NCsNtdgqQHvkwjvR+FQcYPzoAMeyZwyzeBU39nsLvZce+\/+1s1ke8+deo7DgCm4c4UpC2tussQX0jsfEoxg6ijxtlYKygKgUdK9KHR79an12xinWvjQbDY5lp6naCUgZnAVhE4nDLI4UMzufq9xBYllwAMU4zyBypxklvop58yt39icwpF9gf9lvCeELw5E5Rw078f9GwOn4yFTOBzdn8uKhRBii7oFl+ry\/HVJIn8pAyMJxdDjyVxjkCmLyjEiLk7aMmI3H7xTDg5TnoMDeI3iL5YwXR63\/59ho+HODRtN99bDxqTx4AY\/FKyPzceejE12ytkR\/hB7P1G47gmOJmzE7iPkf80n6\/VV5pNVeQG+3WoKWQW4nILq0ynourml4c7PLfptcW75Fw==\" \/> \t\t<a href=\"https:\/\/www.pdf24.org\" target=\"_blank\" title=\"www.pdf24.org\" rel=\"nofollow\"><img src=\"https:\/\/blog.mhasin.eu\/wp-content\/plugins\/pdf24-post-to-pdf\/img\/pdf_32x32.png\" alt=\"\" border=\"0\" height=\"32\" \/><\/a> \t\t<span class=\"pdf24Plugin-cp-space\">&nbsp;&nbsp;<\/span> \t\t<span class=\"pdf24Plugin-cp-text\">Send article as PDF<\/span> \t\t<span class=\"pdf24Plugin-cp-space\">&nbsp;&nbsp;<\/span> \t\t<input class=\"pdf24Plugin-cp-input\" style=\"margin: 0px;\" type=\"text\" name=\"sendEmailTo\" placeholder=\"Enter email address\" \/> \t\t<input class=\"pdf24Plugin-cp-submit\" style=\"margin: 0px;\" type=\"submit\" value=\"Send\" \/> \t<\/form> <\/div>","protected":false},"excerpt":{"rendered":"Pri zablokovan\u00ed root \u00fa\u010dtu je potrebne na ESXi aktivova\u0165 shell a n\u00e1sledne pomocou pr\u00edkazov vy\u010disti\u0165 po\u010d\u00edtadlo neplatn\u00fdch prihl\u00e1sen\u00ed Zobrazenie poctu ne\u00faspe\u0161n\u00fdch prihl\u00e1sen\u00ed root \u00fa\u010dtu do ESXi prostredia: Odomknutie zablokovan\u00e9ho \u00fa\u010dtu: Bezpe\u010dnostne politiky v ESXi je mo\u017ene definova\u0165 pre ka\u017ed\u00e9 ESXi zvl\u00e1\u0161\u0165. ESXi 6.x ma preddefinovan\u00e9 bezpe\u010dnostne politiky sily hesla pre u\u017e\u00edvate\u013eov. Politiky pre heslo platne v ESXi 6.x Heslo mus\u00ed obsahova\u0165 ve\u013ek\u00e9 p\u00edsmena ( A-Z ), male p\u00edsmena ( a-z ), \u010d\u00edslice ( 0-9 )&hellip;\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"arc_restricted_post":false,"footnotes":""},"categories":[2],"tags":[],"class_list":["post-320","post","type-post","status-publish","format-standard","hentry","category-vmware"],"_links":{"self":[{"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/posts\/320","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=320"}],"version-history":[{"count":10,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/posts\/320\/revisions"}],"predecessor-version":[{"id":346,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/posts\/320\/revisions\/346"}],"wp:attachment":[{"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=320"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=320"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=320"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}