lock account after multiple login failure

Earl Ng December 6, 2016

is there an existing function that allows the administrators to enforce a rule that after multiple failed login attempts by a user, that that user's account becomes "locked", and is only unlock-able by the administrator?

 

I know that there is an existing solution that after X number of failed attempts, a Captcha is required, but I was hoping for a "full account lock" solution if possible.

2 answers

0 votes
Peter Geshev
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 7, 2016

Hi Earl,

As Vasiliy has pointed out there is no existing functionality in the product to block the user account. The feature that was implemented was the Captcha. As a workaround you may use firewall utilities to block such requests. One such utility is Fail2Ban

Regards,

Peter

0 votes
Vasiliy Zverev
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 6, 2016

If you want to lock user you should delete it from jira-users and jira-administrators groups.

Unfortunetelly I do not know how to automate it.

Suggest an answer

Log in or Sign up to answer