Hi everyone,
we encounter following jira behaviour. We have a service user which does some REST API stuff.
From time to time it happens that user will be locked for authentication. Even though passwort of the service user never expires and service user is only used for this porpuse (no other and/or manual usage).
Oberservation 1) User will be locked (or at least something happens here), even though authentication might be right
After this, I can see in log.
The user 'xxx' is required to answer a CAPTCHA elevated security check. Failure count equals ...
I thoght this mark a situation where user is locked and can't login anymore. However in another custom log it states that user can still execute stuff.
Observation 2) User still do sucessfull requests via API even it seems that it is locked or CAPCHA is required.
For me this does not match with the jira log.
Any hints on this?
Can somebody explain if I understood CAPCHA behaviour and user locking right?
I thoght that if user has e.g. 3 failed attemps, the user will be locked and user isn't able to login anymore till admin unlock the user. (Maximum Authentication Attempts Allowed)
And what's the deal with CAPCHA here?
User is from conected AD.
Thanks in Advance.
Andreas