Oscar,

Throttle settings are a ratio (threshold:rangeSeconds), so you have one attempt 
in 1800s. Probably a little long for human error ;)

If you want to include IP address you will most likely have to use one of the 
systems listed at the bottom of the page, 
https://apereo.github.io/cas/6.4.x/authentication/Configuring-Authentication-Throttling.html

Ray


On Wed, 2022-03-16 at 10:27 -0700, Oscar Eduardo Cruz Lesmes wrote:
Notice: This message was sent from outside the University of Victoria email 
system. Please be cautious with links and sensitive information.

Hello,
I am configuring the failed login attempts control policy to lock the account 
after three attempts with the following configuration.

[CAS.jpg]

When performing the test after 3 attempts in the 4, the account is blocked for 
a few minutes, but not for 60 minutes as it appears in the rangeSeconds=3600 
parameter.

Also, when I open a different web browser where I did the first test, the 
system allows me to enter and should not allow it since the account should be 
blocked.

Please know if another person has already made this configuration and how to do 
it.

Thanks for your help.


-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/0aab53a385d844f3ffef6dc58495b99303f5fd74.camel%40uvic.ca.

Reply via email to