]
Darran Lofthouse moved WFLY-569 to ELY-297:
-------------------------------------------
Project: WildFly Elytron (was: WildFly)
Key: ELY-297 (was: WFLY-569)
Component/s: HTTP
Realms
SASL
(was: Domain Management)
(was: Security)
Fix Version/s: (was: 11.0.0.Alpha1)
Implement an account lockout mechanism for domain management.
-------------------------------------------------------------
Key: ELY-297
URL:
https://issues.jboss.org/browse/ELY-297
Project: WildFly Elytron
Issue Type: Task
Components: HTTP, Realms, SASL
Reporter: Darran Lofthouse
Assignee: Darran Lofthouse
Labels: Common_Authentication, Realm_Management, management_security,
One issue to consider is that we are using realms to integrate with existing user stores
so may not be able to update the remote store: -
- Consider an option to update the remote store if possible.
- If not cache a backlisted user until an admin unlocks that account
Before being implemented this feature will require further discussion, in additional to
locking mechanisms for unlocking should also be considered and also the potentional for
denail of service type attacks based on locking out the administrators.