Uploaded image for project: 'WildFly Elytron'
  1. WildFly Elytron
  2. ELY-2891

Add Utility that can wrap SecurityRealm to provide brute force back off protection for username / password auth

    • Icon: Enhancement Enhancement
    • Resolution: Unresolved
    • Icon: Critical Critical
    • 2.7.0.CR1
    • None
    • Realms
    • None

      The idea of the utility is that after so many failed authentications the realm should for a period of time act as though all further attempts are invalid regardless of if they are.

      If further attempts occur the back off period should increase although with caution that we don't back off until the end of time.

      State will be kept in memory so only survive until the next server reload.

      It should be possible to tune the back off configuration.

      It should also be possible to unlock one or all identities so this utility does not become it's own DoS mechanism.

              darran.lofthouse@redhat.com Darran Lofthouse
              darran.lofthouse@redhat.com Darran Lofthouse
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: