Shibboleth - Account Lock Out

Matthew Slowe M.Slowe at kent.ac.uk
Fri Feb 20 13:46:22 EST 2015


(For DSEE 5 etc, on which 389 is based) No, if you want correctly applied account lockout then the BINDs must be made against the masters.

--
foo
Sent from my mobile device

On 20 Feb 2015, at 17:19, Joshua Brodie <josbrodie at gmail.com<mailto:josbrodie at gmail.com>> wrote:

Hi List:

Question that is not strictly shibboleth related - but this list may have the better knowledge base.

Shibboleth bind user/password against multi-master replication LDAP (389 Directory Server).

All works as expected.

We are obliged to introduce account lockouts for X many failed binds in Y minutes - this works as expected as well.

The challenge: Shibboleth connects to the consumer servers in the LDAP MMR (the user's incorrect bind attempts are local to the Consumer server - i.e. do not seem to replicate among the consumers).

We don't want to switch binds to the Supplier servers - how do you resolve this? Is there a way to replicate 'PasswordLockout' or 'PasswordRetryCount' among the Consumers?


Thanks.




--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150220/220e2208/attachment.html 


More information about the users mailing list