Re: Add. comments on Kdc model, WAS[Re: I-D Action: draft-ietf-krb-wg-kdc-model-12.txt]

Nico Williams <[email protected]> Mon, 4 Jun 2012 14:24:50 -0500
Newsgroups gmane.ietf.krb-wg
Message-ID <CAK3OfOhSVz2XwSVj9NC5K0575TQx9HPn+kdoWDh8jyG9i=PGEA@mail.gmail.com>
On Mon, Jun 4, 2012 at 2:20 PM, Greg Hudson <[email protected]> wrote:
> On 06/04/2012 09:20 AM, Sam Hartman wrote:
>> I'd like to ask the WG whether we want to support lockouts depending on
>> how many failed authentications there have been since last successful
>> authentication.
>
> MIT krb5 does this and Active Directory does this (I believe), so yes, I
> think it's important to support that if we're going to be talking about
> lockout counters in the information model.

But it's not exact.  At least not for AD and not for MIT with a db2 backend.

Nico
--
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg