nano /etc/security/faillock.conf
=======================
audit
silent
no_log_info
deny = 3
fail_interval = 3600
unlock_time = 3600
even_deny_root
root_unlock_time = 3600
sudo nano /etc/pam.d/common-auth
=======================
auth required pam_faillock.so preauth
auth [success=1 default=ignore] pam_unix.so nullok
auth [default=die] pam_faillock.so authfail
auth sufficient pam_faillock.so authsucc
auth requisite pam_deny.so
auth required pam_permit.so
auth optional pam_cap.so
nano /etc/pam.d/common-account
=======================
account required pam_faillock.so
account [success=1 new_authtok_reqd=done default=ignore] pam_unix.so
account requisite pam_deny.so
account required pam_permit.so