Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungThe Code Style Rules Worth Arguing About(20.09.2026 um 04:45 Uhr)
Sichere ProgrammierungHow Image Translation Actually Works: From Pixels to Translated Text(20.09.2026 um 05:13 Uhr)
Linux Tipps & HardeningConvey is a GTK4/libadwaita fork of Linux email app Geary(20.09.2026 um 03:31 Uhr)
IT Security Toolsmythic_telegram_profile(20.09.2026 um 03:28 Uhr)
Sichere ProgrammierungThe Code Style Rules Worth Arguing About(20.09.2026 um 04:45 Uhr)
Sichere ProgrammierungHow Image Translation Actually Works: From Pixels to Translated Text(20.09.2026 um 05:13 Uhr)
Linux Tipps & HardeningConvey is a GTK4/libadwaita fork of Linux email app Geary(20.09.2026 um 03:31 Uhr)
IT Security Toolsmythic_telegram_profile(20.09.2026 um 03:28 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

How do you interpret JSIG AC-10?

Hello all,

I am curious if anyone has to deal with the JSIG AC-10 control in their environment. As a reminder, here it is:

AC-10 CONCURRENT SESSION CONTROL Control: The information system limits the number of concurrent sessions for each non-privileged and privileged to maximum of three (3) sessions. Supplemental Guidance: Organizations may define the maximum number of concurrent sessions for information system accounts globally, by account type (e.g., privileged user, non-privileged user, domain, specific application), by account, or a combination. For example, organizations may limit the number of concurrent sessions for system administrators or individuals working in particularly sensitive domains or mission-critical applications. This control addresses concurrent sessions for information system accounts and does not address concurrent sessions by single users via multiple system accounts. This control may require third party software or development of a script. 

I have a solution set up in my environment that tracks how many logons a person does (stored in sqlite3 db). In my pam.d files, I have it check on logon and denies a person from opening more than 3 (ssh, console, xrdp) sessions. It works pretty good although annoying when I want to open a bunch of sessions on patch weekend.

I am starting to question why that might matter. What I would more than likely expect to see is "control how many concurrent sessions per machine there are". This certainly seems to be what RHEL-09-412040 talks about, which is /etc/security/limits.conf "maxlogins". That could help prevent DDOS.

How do you interpret this? How do you meet this control in your environments?

submitted by /u/Hxcmetal724
[link] [comments]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten How do you interpret JSIG AC-10?

Thematisch verwandte Begriffe: interpret, JSIG, AC10 · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93987 | rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerabi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick