Does JBoss provide Brute Force attack protection and account lockout mechanism?
Issue
- Does JBoss support account locking if invalid credentials are provided for 'n' number of times
- Is there any configuration that can be made to support user account locking on the JBoss side after subsequent failed login attempts?
- Is there a Brute Force attack protection / detection in JBoss EAP?
Environment
- Red Hat JBoss Enterprise Application Platform (EAP)
- 8.x
- 7.x
- 6.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.