<div dir="ltr"><div><div><div><div><div><div><div>Hi List:<br><br></div>Question that is not strictly shibboleth related - but this list may have the better knowledge base.<br><br></div>Shibboleth bind user/password against multi-master replication LDAP (389 Directory Server).<br><br></div>All works as expected.<br><br></div>We are obliged to introduce account lockouts for X many failed binds in Y minutes - this works as expected as well.<br><br></div>The challenge: Shibboleth connects to the consumer servers in the LDAP MMR (the user&#39;s incorrect bind attempts are local to the Consumer server - i.e. do not seem to replicate among the consumers).<br><br></div>We don&#39;t want to switch binds to the Supplier servers - how do you resolve this? Is there a way to replicate <span style="color:rgb(0,0,0);font-family:&quot;Segoe UI&quot;,Helvetica,Arial,sans-serif;font-size:13.3333px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;display:inline!important;float:none">&#39;PasswordLockout</span>&#39; or &#39;PasswordRetryCount&#39; among the Consumers? <br><br><br></div>Thanks.<br><div><br><br><div><div><br><br></div></div></div></div>