users@glassfish.java.net

Re: Automatic user lockout

From: <forums_at_java.net>
Date: Thu, 21 Feb 2013 04:41:03 -0600 (CST)

User lockout is a complex thing. A simpler approach might be to just add a
one second wait for each consecutive failed login attempt. That would stop
any dictionary attack. I agree that it is important that Glassfish is
equipped with something of this sort out-of-the-box.

--
[Message sent by forum member 'tmpsa']
View Post: http://forums.java.net/node/703075