<def-group>
  <definition class="compliance" id="accounts_password_pam_faillock" version="1">
    <metadata>
      <title>Check pam_faillock Existence in system-auth</title>
      <affected family="unix">
        <platform>multi_platform_all</platform>
      </affected>
      <description>Check that pam_faillock.so exists in system-auth</description>
    </metadata>
    <criteria>
      <criterion comment="Conditions for pam_faillock are satisfied"
      test_ref="test_accounts_password_pam_faillock" />
    </criteria>
  </definition>

  <ind:textfilecontent54_test check="all" comment="check the configuration of /etc/pam.d/system-auth" id="test_accounts_password_pam_faillock" version="1">
    <ind:object object_ref="obj_accounts_password_pam_faillock" />
  </ind:textfilecontent54_test>

  <ind:textfilecontent54_object id="obj_accounts_password_pam_faillock" version="1">
    <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
    <ind:pattern operation="pattern match">^\s*password\s+(?:(?:required)|(?:requisite))\s+pam_faillock\.so.*$</ind:pattern>
    <ind:instance datatype="int">1</ind:instance>
  </ind:textfilecontent54_object>

</def-group>
