Stop your users from locking themselves out when they forget their password
User & Group Management
Stop your users from locking themselves out when they forget their password
🧩 The Challenge
Dealing with a dev who hits their bad password limit three times in a row and gets completely kicked out of the server is a total headache. You end up having to jump into a different terminal just to unlock them, which is a waste of everyone’s time.
💡 The Fix
Use the faillock tool to check who is actually blocked and clear the failure count without needing to resort to manual password resets. It saves you from having to look up account lock settings every time someone goes on a typing spree.
faillock --user <username> --reset
⚙️ Why It Works
This utility maintains a directory of failed attempts under /var/run/faillock, and running the reset flag simply wipes those metadata files for that specific user. It’s cleaner than messing with pam_tally, which is pretty much dead on modern distros.
🚀 Pro-Tip: Alias this to unlock-user in your bashrc so you can stop hunting for the syntax when you’re in a hurry.
Linux Tips & Tricks | © ngelinux.com | 7/26/2026
