Login throttling

Cantor, Scott cantor.2 at osu.edu
Thu Aug 4 12:29:08 EDT 2016


On 8/4/16, 11:58 AM, "users on behalf of Richard Frovarp" <users-bounces at shibboleth.net on behalf of richard.frovarp at ndsu.edu> wrote:

>    Is there anything built in to IdP v3 that can do login throttling?

No.

> This would prevent a 
>    remote system from doing a DoS against an account, and prevent searching 
>    for the accounts with a password of "Password1".

I'd love to see evidence anybody still does this, because I don't believe it. Phishing is too simple.

> I have mod_security available to use. I could use that if I knew of all 
> of the URLs where a login could be posted.

That depends on the login flow, but for Password, the URLs are essentially the SSO profile endpoints in the system.

-- Scott




More information about the users mailing list