<div dir="ltr">Thanks!<div><br></div><div>I find the following in multi-context-broker.xml - is that the place to change?  Does a value of -1 create an unsafe vulnerability?<div><br></div><div>







<p class=""><span class=""> &lt;!-- </span></p>
<p class=""><span class="">        The maximum number of </span><span class="">fail</span><span class="">ures allowed a user before returning a SAML </span><span class="">fail</span><span class="">ure to the</span></p>
<p class=""><span class="">        relying party. Must be specified according to schema definition. Set to a value of -1</span></p>
<p class=""><span class="">        to allow an unlimited number of login </span><span class="">fail</span><span class="">ures.</span></p>
<p class=""><span class="">     --&gt;</span></p>
<p class=""><span class="">    &lt;maxFailures&gt;3&lt;/maxFailures&gt;</span></p><p class=""><span class=""><br></span></p><p class=""><span class=""><br></span></p></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Apr 3, 2015 at 10:37 AM, Paul Hethmon <span dir="ltr">&lt;<a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



<div dir="auto">
<div>There&#39;s an option for max fails in the MCB config. Set it to a higher value or disable it. I think there was a bug in some versions where the disabled option was not honored but setting it to 999 would definitely work. </div>
<div><br>
</div>
<div>Paul<br>
<br>
<div><br>
</div>
(Please enjoy the autocorrect features if this phone)</div><div><div class="h5">
<div><br>
On Apr 3, 2015, at 2:21 PM, IAM David Bantz &lt;<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>&gt; wrote:<br>
<br>
</div>
<blockquote type="cite">
<div>
<div dir="ltr">If a user fails authN at the IdP three times, our IdP is redirecting the browser to the SP.
<div>
<div><br>
</div>
<div>That&#39;s generally not helpful, leaving the user on a generic SP error page.</div>
<div><br>
</div>
<div>Shibboleth IdP 2.4 with MCB.</div>
<div><br>
</div>
<div>I&#39;m seeing the following suspicious entries in the IdP log:</div>
</div>
<div><br>
</div>
<div>
<p><span>10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:207] - submodule process login returned [false]</span></p>
<p><span>10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:312] - Current failed login count = [3]</span></p>
<p><span>10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:156] - Authentication result = [true]</span></p>
<p><span>10:10:57.520 - INFO [Shibboleth-Access:73] - 20150403T181057Z|172.20.233.117|<a href="http://idp.alaska.edu" target="_blank">idp.alaska.edu</a>:443|/profile/SAML2/Redirect/SSO|</span></p>
<p>What&#39;s going on??</p>
<p>David Bantz</p>
</div>
</div>
</div>
</blockquote>
</div></div><span class="HOEnZb"><font color="#888888"><blockquote type="cite">
<div><span>-- </span><br>
<span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a></span></div>
</blockquote>
</font></span></div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>