FeministWiki:LDAP Schema: Difference between revisions

 
Line 149: Line 149:
  pwdAttribute: userPassword
  pwdAttribute: userPassword
  pwdLockout: TRUE
  pwdLockout: TRUE
pwdFailureCountInterval: 3600
  pwdLockoutDuration: 3600
  pwdLockoutDuration: 3600
  pwdMaxFailure: 10
  pwdMaxFailure: 30
pwdFailureCountInterval: 3600
  EOF
  EOF
   
   
Line 162: Line 162:
  EOF
  EOF


With these settings, ten consecutive authentication failures with a username will lock the account for an hour.  Login failures are also cleared after an hour.  This means it's possible to try ten passwords per hour during a brute-force attack, which won't get the attacker very far.
With these settings, 30 consecutive authentication failures with a username will lock the account for an hour.  Login failures are also cleared after an hour, meaning it's possible to try 30 passwords per hour, which won't get an attacker far.


=== Time of last login ===
=== Time of last login ===