User Account Policy

Hi,
i have the following config in the system-auth files

auth        required      /lib/security/$ISA/pam_env.so
auth        sufficient    /lib/security/$ISA/pam_unix.so likeauth nullok
auth        required      /lib/security/$ISA/pam_deny.so

account     required      /lib/security/$ISA/pam_unix.so
account     sufficient    /lib/security/$ISA/pam_succeed_if.so uid < 100 quiet
account     required      /lib/security/$ISA/pam_permit.so

password    requisite     /lib/security/$ISA/pam_cracklib.so retry=3 minlen=8 lcredit=-1 ucredit=-1 dcredit=-1 ocredit=-1
password    sufficient    /lib/security/$ISA/pam_unix.so nullok use_authtok md5 shadow
password    required      /lib/security/$ISA/pam_deny.so

session     required      /lib/security/$ISA/pam_limits.so
session     required      /lib/security/$ISA/pam_unix.so

and i want a user to be able to try to enter a password on 3 time then the account shall be locked for 60 secondes. HAving a look to some post i tried the following:

auth        required      /lib/security/$ISA/pam_env.so
#auth        required      /lib/security/$ISA/pam_tally.so onerr=fail deny=3 unlock_time=60
auth        required      /lib/security/$ISA/pam_tally.so deny=3 unclok_time=60
auth        sufficient    /lib/security/$ISA/pam_unix.so likeauth nullok
auth        required      /lib/security/$ISA/pam_deny.so

account     required      /lib/security/$ISA/pam_unix.so
account     required      /lib/security/$ISA/pam_tally.so reset
account     sufficient    /lib/security/$ISA/pam_succeed_if.so uid < 100 quiet
account     required      /lib/security/$ISA/pam_permit.so

password    requisite     /lib/security/$ISA/pam_cracklib.so try_first_pass retry=3 minlen=8 lcredit=-1 ucredit=-1 dcredit=-1 ocredit=-1
password    sufficient    /lib/security/$ISA/pam_unix.so nullok use_authtok md5 shadow
password    required      /lib/security/$ISA/pam_deny.so

session     required      /lib/security/$ISA/pam_limits.so
session     required      /lib/security/$ISA/pam_unix.so

but still test in unsucessfull. i need the help of an expert urgently,

thanks

Try pam_tally2.so instead of pam_tally.so.

#auth        required      /lib/security/$ISA/pam_tally.so onerr=fail deny=3 unlock_time=60
auth        required      /lib/security/$ISA/pam_tally.so deny=3 unclok_time=60

maybe a spell check? unclok_time should read unlock_time?