Hello all,
we'd like to open up our jira instance to some external users (2 for starters). Our current users are authenticated via JIRA Delegated Authentication Directory, while those external users ( and a few jira-admins) are defined in JIRA Internal Directory.
The JIRA Delegated Authentication Directory connects to our central active directory, which holds all our users.
Now our security guru wants to stop us. He reckons "there are billions of people out there, that could enter some of our internal user names, use a wrong password three time and with this LOCK OUT our unsuspecting active directory users. I cannot allow this."
He's right, unsuccessful login-attempts DO in fact disable user-accounts in AD. Malicious use is possible.
Is there any way to prevent this?
(changing our current AD account lockout policy being not an option)
Cheers
Axel Joester