Hi All I am planning to use pam_tally for console login to the server. Now I like use it only for root account and no other user. In other words only for root account allow 3 try and then lock it out until someone manually reset it. We have system admin users who have full sudo access to do that. User's do not need to be tallied becasue they all use SecurID for authentication which has been setup to lock account after 3 fail tries. Is that possible or should I look for a different solution? Thanks for any feedback -- Asif Iqbal PGP Key: 0xE62693C5 KeyServer: pgp.mit.edu "...it said: Install Windows XP or better...so I installed Solaris..." _______________________________________________ Pam-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/pam-list