<div dir="ltr">Thanks,<div><br></div><div>I set and verified a finite retry limit of 99; I don&#39;t expect any real user to reach 99 (though I did to test) but won&#39;t allow some bot to endlessly submit and trigger authN attempts.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Apr 3, 2015 at 5:03 PM, Paul Hethmon <span dir="ltr">&lt;<a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



<div dir="auto">
<div><span></span></div>
<div>
<div>That&#39;s it. A value of -1 should allow unlimited retries, at least in the MCB logic, individual auth modules could do there own thing. </div>
<div><br>
</div>
<div>Just be aware that logic had a bug at one point. GitHub may have an issue listed about it. </div><span class="">
<div><br>
</div>
<div>Paul<br>
<br>
<div><br>
</div>
(Please enjoy the autocorrect features if this phone)</div>
</span><div><div class="h5"><div><br>
On Apr 3, 2015, at 2:45 PM, IAM David Bantz &lt;<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>&gt; wrote:<br>
<br>
</div>
<blockquote type="cite">
<div>
<div dir="ltr">Thanks!
<div><br>
</div>
<div>I find the following in multi-context-broker.xml - is that the place to change?  Does a value of -1 create an unsafe vulnerability?
<div><br>
</div>
<div>
<p><span> &lt;!-- </span></p>
<p><span>        The maximum number of </span><span>fail</span><span>ures allowed a user before returning a SAML
</span><span>fail</span><span>ure to the</span></p>
<p><span>        relying party. Must be specified according to schema definition. Set to a value of -1</span></p>
<p><span>        to allow an unlimited number of login </span><span>fail</span><span>ures.</span></p>
<p><span>     --&gt;</span></p>
<p><span>    &lt;maxFailures&gt;3&lt;/maxFailures&gt;</span></p>
<p><span><br>
</span></p>
<p><span><br>
</span></p>
</div>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Fri, Apr 3, 2015 at 10:37 AM, Paul Hethmon <span dir="ltr">
&lt;<a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="auto">
<div>There&#39;s an option for max fails in the MCB config. Set it to a higher value or disable it. I think there was a bug in some versions where the disabled option was not honored but setting it to 999 would definitely work. </div>
<div><br>
</div>
<div>Paul<br>
<br>
<div><br>
</div>
(Please enjoy the autocorrect features if this phone)</div>
<div>
<div>
<div><br>
On Apr 3, 2015, at 2:21 PM, IAM David Bantz &lt;<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>&gt; wrote:<br>
<br>
</div>
<blockquote type="cite">
<div>
<div dir="ltr">If a user fails authN at the IdP three times, our IdP is redirecting the browser to the SP.
<div>
<div><br>
</div>
<div>That&#39;s generally not helpful, leaving the user on a generic SP error page.</div>
<div><br>
</div>
<div>Shibboleth IdP 2.4 with MCB.</div>
<div><br>
</div>
<div>I&#39;m seeing the following suspicious entries in the IdP log:</div>
</div>
<div><br>
</div>
<div>
<p><span>10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:207] - submodule process login returned [false]</span></p>
<p><span>10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:312] - Current failed login count = [3]</span></p>
<p><span>10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:156] - Authentication result = [true]</span></p>
<p><span>10:10:57.520 - INFO [Shibboleth-Access:73] - 20150403T181057Z|172.20.233.117|<a href="http://idp.alaska.edu" target="_blank">idp.alaska.edu</a>:443|/profile/SAML2/Redirect/SSO|</span></p>
<p>What&#39;s going on??</p>
<p>David Bantz</p>
</div>
</div>
</div>
</blockquote>
</div>
</div>
<span><font color="#888888">
<blockquote type="cite">
<div><span>-- </span><br>
<span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a></span></div>
</blockquote>
</font></span></div>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
</blockquote>
</div>
<br>
</div>
</div>
</blockquote>
<blockquote type="cite">
<div><span>-- </span><br>
<span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a></span></div>
</blockquote>
</div></div></div>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>