Shibboleth - Account Lock Out
Joshua Brodie
josbrodie at gmail.com
Fri Feb 20 12:19:28 EST 2015
Hi List:
Question that is not strictly shibboleth related - but this list may have
the better knowledge base.
Shibboleth bind user/password against multi-master replication LDAP (389
Directory Server).
All works as expected.
We are obliged to introduce account lockouts for X many failed binds in Y
minutes - this works as expected as well.
The challenge: Shibboleth connects to the consumer servers in the LDAP MMR
(the user's incorrect bind attempts are local to the Consumer server - i.e.
do not seem to replicate among the consumers).
We don't want to switch binds to the Supplier servers - how do you resolve
this? Is there a way to replicate 'PasswordLockout' or 'PasswordRetryCount'
among the Consumers?
Thanks.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150220/15482c32/attachment.html
More information about the users
mailing list