shibboleth-dev - Re: [Shib-Dev] Account lockout
Subject: Shibboleth Developers
List archive
- From: Chad La Joie <>
- To:
- Subject: Re: [Shib-Dev] Account lockout
- Date: Wed, 23 Mar 2011 13:34:53 -0400
If this is important behavior why isn't your IdM system doing that?
What you describe is pretty much useless unless every single system is
doing it. And if every system isn't doing it, and thus the feature
isn't effective, why would you want it in the IdP?
On Wed, Mar 23, 2011 at 13:11, Christopher Bongaarts
<>
wrote:
> Has anyone implemented an "attack lock" (X failed password attempts without
> a success in Y minutes locks out further attempts for Z minutes) for the
> IdP?
>
> If not, would the StorageService be a good place to keep the necessary
> state?
> --
> %% Christopher A. Bongaarts %%
>
> %%
> %% OIT - Identity Management %% http://umn.edu/~cab %%
> %% University of Minnesota %% +1 (612) 625-1809 %%
>
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
- [Shib-Dev] Account lockout, Christopher Bongaarts, 03/23/2011
- Re: [Shib-Dev] Account lockout, Andrew Petro, 03/23/2011
- Re: [Shib-Dev] Account lockout, Chad La Joie, 03/23/2011
- Re: [Shib-Dev] Account lockout, Christopher Bongaarts, 03/23/2011
- RE: [Shib-Dev] Account lockout, Dergenski, Todd A., 03/24/2011
Archive powered by MHonArc 2.6.16.