From: | "Subu Ayyagari" <s.ayyagari@xpedite.com> |
To: | <krb5-bugs@mit.edu> |
Cc: | "Subramanyam v Ayyagari" <s.ayyagari@xpedite.com> |
Subject: | FW: account lockup after invalid login attempts |
Date: | Thu, 17 Jul 2003 15:54:04 -0400 |
Hi,
Problem Description:
I wish to implement account lockout policy. When a user exceeds 5 invalid
login attempts, I wish to disable his account
I am using Kerberos 1.2.8 on SUN Solaris 9
I have enabled pre-authentication, so the server knows about these invalid
AS_REQ
requests, and I see them in the logs.
Microsoft WIndows implementation..hmmmm pardon me for using the W word :)...
does have this account lockout feature.
The security folks here are surprised when I tell them
that kerberos does not support account lockup.
Please suggest.
regards,
subu ayyagari
732-389-3900 x7227
s.ayyagari@xpedite.com
Problem Description:
I wish to implement account lockout policy. When a user exceeds 5 invalid
login attempts, I wish to disable his account
I am using Kerberos 1.2.8 on SUN Solaris 9
I have enabled pre-authentication, so the server knows about these invalid
AS_REQ
requests, and I see them in the logs.
Microsoft WIndows implementation..hmmmm pardon me for using the W word :)...
does have this account lockout feature.
The security folks here are surprised when I tell them
that kerberos does not support account lockup.
Please suggest.
regards,
subu ayyagari
732-389-3900 x7227
s.ayyagari@xpedite.com