Temporary Locking Settings
Description
These settings configure temporary user locking.
May be used by
Properties
Base Duration [ms] (
baseDurationInMs) Description
After an unsuccessful login a delay of a certain amount of time is produced to make brute-force-attacks more difficult. This setting defines the number of milliseconds to wait before showing the login page again after an unsuccessful login.
Attributes
Integer
Optional
Default value
3000
Exponential Factor (
exponentialLockoutFactor) Description
If this property has a value greater than 1 then the delay after failed logins is increased with every failed login (per user): After the first failed login, the delay is as specified by property Base Duration. After the second failure, the delay is multiplied by the factor specified by this property, after the third it is again multiplied by this factor etc. After n failed logins, the delay is
(Base Duration) * (Exponential Factor)^(n-1) + (Additional Duration)*(n-1)
Example: If the exponential factor is 2.0, then the delay is doubled with every failed login. Note that this property can be combined with property Additional Duration.Attributes
Double
Optional
Default value
1.0
Additional Duration (in ms) (
linearLockoutFactor) Description
If this property has a value greater than 0 (zero) then the delay after failed logins is increased with every failed login (per user): After the first failed login, the delay is as specified by property Base Duration. After the second failure, the amount of milliseconds specified by this property is added. It is again added after the third failed login, etc. After n failed logins, the delay is (in milliseconds):
(Base Duration) * (Exponential Factor)^(n-1) + (Additional Duration)*(n-1) – Notice that the first part is always >=(Base Duration)
Note that this property can be combined with property Exponential Factor.Attributes
Integer
Optional
Default value
0
Lockout Message Threshold (
lockoutMessageThreshold) Description
If the exponential factor is used, long delays may arise which may result in connection timeouts if the response is just held back. Therefore it makes sense to display a message to the user if a certain amount of delay is exceeded. This property specifies the threshold for this delay in milliseconds. If the login failure delay is longer than the value of this property, a message is displayed to the user rather than blocking the request. No value or a value of zero disables this feature.
Attributes
Integer
Optional
Default value
0
Delay Between Login Steps (
delayBetweenLoginSteps) Description
Delays responses to the client when asking for another authentication step (e.g. OTP after entering username and password) for the specified number of milliseconds.
Enhances security because it makes it impossible for an attacker to tell whether the first factor was wrong or correct based on timing.
Choose a value larger than the slowest expected response from the system checking the first factor.
Attributes
Integer
Optional
Default value
500
YAML Template (with default values)
type: TemporaryLockingSettings
id: TemporaryLockingSettings-xxxxxx
displayName:
comment:
properties:
baseDurationInMs: 3000
delayBetweenLoginSteps: 500
exponentialLockoutFactor: 1.0
linearLockoutFactor: 0
lockoutMessageThreshold: 0