Solved

Number of failed login attempts (Indicium legacy)

  • 21 October 2021
  • 4 replies
  • 50 views

Userlevel 2
Badge +10

When using indicium (legacy), a user will be locked out after an x number of wrong login attempts.

My question:

  • Is it possible to change the number of allowed login attempts? Extended propery perhaps.
  • Can the number of minutes a user becomes locked out be changed? Extended propery perhaps.
  • Can Thinkwise change the message a user gets after reaching the number of failed attemtps?

Currently the message: “username and password combination is wrong” is NOT correct. After applying the correct password the message stays the same…. One has to wait the number of minutes shown in the indicium log (see below).

Ideally the message should read “You are locked out for another 4 minutes because of wrong cridentials”

Log (example)

2021-10-21T13:23:58.2391860+02:00 0HMC4OISQL7AA:0000004A [ERR] Login failed for 'Klaas.Vaak@home.nl' because the maximum number of failed login attempts was exceeded. Retrying is disabled for another 5 minutes. (26a1e4c9)
2021-10-21T13:23:58.3016692+02:00 0HMC4OISQL7AF:00000035 [ERR] Login failed for 'Klaas.Vaak@home.nl' because the maximum number of failed login attempts was exceeded. Retrying is disabled for another 5 minutes. (26a1e4c9)
2021-10-21T13:24:27.0564736+02:00 0HMC4OISQL7AB:0000003F [ERR] Login failed for 'Klaas.Vaak@home.nl' because the maximum number of failed login attempts was exceeded. Retrying is disabled for another 4 minutes. (7095007d)
2021-10-21T13:24:27.1345968+02:00 0HMC4OISQL7AC:0000003B [ERR] Login failed for 'Klaas.Vaak@home.nl' because the maximum number of failed login attempts was exceeded. Retrying is disabled for another 4 minutes. (7095007d)


 

icon

Best answer by Mark Jongeling 29 October 2021, 14:37

View original

4 replies

Userlevel 7
Badge +19

Hi Henri:

  • Is it possible to change the number of allowed login attempts? Extended property perhaps.

This is not possible, feel free to create an idea for this to be configurable.

  • Can the number of minutes a user becomes locked out be changed? Extended property perhaps.

This is also not possible, feel free to create another idea for this to be configurable.

  • Can Thinkwise change the message a user gets after reaching the number of failed attempts?

According to my colleague this is a bug in the Mobile GUI.

Userlevel 7
Badge +19

Hi Henri,

I had to edit my reply, my colleague told me the last question is a bug in the Mobile GUI. Could you report this in TCP? 

Userlevel 2
Badge +2

@htimmermans - I could use your upvote here: Failed logins logging and locking accounts when using IAM for access control | Thinkwise Community (thinkwisesoftware.com)

 

Userlevel 2
Badge +10

Done

Reply