#2582 Prevent offline guessing attacks
Closed: Invalid Opened by jhrozek.

If the sssd_be process is offline, the account can't typically be locked out since the server, which normally keeps track of the lockout threshold is not contacted.

We should implement a configurable counter that allows the admin to set an offline lockout status.


As Sumit reminded me, we already have offline_failed_login_attempts. I'm sorry, I forgot about this option.

Closing. That was easy :-)

resolution: => invalid
status: new => closed

Re-setting priority of 1.13 backlog tickets used for planning.

priority: critical => major

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 1.13 backlog

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/3623

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata