Project

General

Profile

Actions

Refactor #22778

closed

Allow admin to opt-out from the Brute-force attack protection

Added by roman plevka about 6 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Security
Target version:
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

Implementation of http://projects.theforeman.org/issues/4238 introduced a BFA protection, however this is not configurable at all (enable/disable, number of retries, blacklist timeout, etc.).

It would be beneficial, if I as an admin had a way of configure or completely disable the feature.

- e.g. our automation, running on a single foreman instance executes multiple tests, one of them being a negative tests trying an invalid authentication - this test typically lock the automation out from Foreman access, causing all further tests to fail.


Related issues 1 (0 open1 closed)

Related to Foreman - Feature #4238: Protection from Brute Force Password Attacks ClosedTomer Brisker02/03/2014Actions
Actions

Also available in: Atom PDF