Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0038652Openbravo ERPC. Securitypublic2018-05-29 16:312018-06-04 09:17
alostale 
alostale 
normalminorhave not tried
closedfixed 
5
 
3.0PR18Q3 
caristu
Core
No
0038652: security default: delay response after failed login attempt
In order to mitigate possible brute-force attacks [1], it is possible to configure some delay in the response after failed login attempts.

Even this is configurable [2], by default it is disabled.


---
[1] https://en.wikipedia.org/wiki/Brute-force_attack [^]
[2] http://wiki.openbravo.com/wiki/Openbravo.properties#Log_in_security [^]
-
New instances should have this feature enabled by default with:
* 200ms of increment after each consecutive failed login attempt
* up to 3 seconds of maximum delay
* there will be no user locking by default

Existing instance will keep their current configuration
No tags attached.
depends on defect 0038651 closed alostale problems in user locking implementation 
Issue History
2018-05-29 16:31alostaleNew Issue
2018-05-29 16:31alostaleAssigned To => alostale
2018-05-29 16:31alostaleModules => Core
2018-05-29 16:31alostaleTriggers an Emergency Pack => No
2018-05-29 16:31alostaleRelationship addeddepends on 0038651
2018-05-29 16:34alostaleProposed Solution updated
2018-05-30 09:19hgbotCheckin
2018-05-30 09:19hgbotNote Added: 0104799
2018-05-30 09:19hgbotStatusnew => resolved
2018-05-30 09:19hgbotResolutionopen => fixed
2018-05-30 09:19hgbotFixed in SCM revision => http://code.openbravo.com/erp/devel/pi/rev/31ee92fe5dd441e2ffac6a8ebda8f9a07894478a [^]
2018-06-01 09:34alostaleReview Assigned To => caristu
2018-06-04 09:17caristuNote Added: 0104902
2018-06-04 09:17caristuStatusresolved => closed
2018-06-04 09:17caristuFixed in Version => 3.0PR18Q3

Notes
(0104799)
hgbot   
2018-05-30 09:19   
Repository: erp/devel/pi
Changeset: 31ee92fe5dd441e2ffac6a8ebda8f9a07894478a
Author: Asier Lostalé <asier.lostale <at> openbravo.com>
Date: Tue May 29 16:36:25 2018 +0200
URL: http://code.openbravo.com/erp/devel/pi/rev/31ee92fe5dd441e2ffac6a8ebda8f9a07894478a [^]

fixes 38652: delay response after failed login attempt by default

  New instances will increse response time in 200ms after each subsequent
  failed login attempt up to 3 seconds.

---
M config/Openbravo.properties.template
---
(0104902)
caristu   
2018-06-04 09:17   
Code reviewed + tested OK.