Uploaded image for project: 'Geronimo'
  1. Geronimo
  2. GERONIMO-419

Lockout after N failed logins

    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 1.0-M2
    • 1.0
    • security
    • None

    Description

      It would be nice if the default security realms supported locking an account after a certain number of consecutive failed logins. Lacking that, it would be nice if they supported a configurable delay on a failed login attempt. Both methods help defend against brute force login attacks.

      This is a pretty low priority, but IMHO it still goes on the "nice to have" list.

      Attachments

        Activity

          People

            ammulder Aaron Mulder
            ammulder Aaron Mulder
            Votes:
            1 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: