<html>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
Hi Aivo,<br>
<br>
I believe the user will be automatically unlocked in (fixed) 15 or
30 minutes if I remember correctly. Not sure where this is defined.<br>
<br>
However, the security policy regarding user locking has been
significantly enhanced in upcoming 3.4 release, (current master)
where you can define your own policy and refer to it in System
Configuration. Admin can also unlock user manually (I tested this a
few days ago, e.g. <a class="moz-txt-link-freetext" href="https://jira.evolveum.com/browse/MID-2606">https://jira.evolveum.com/browse/MID-2606</a>).
Current state (Normal/Locked) is displayed.<br>
<br>
The default security policy is included with midpoint, see
<a class="moz-txt-link-freetext" href="https://github.com/Evolveum/midpoint/blob/master/gui/admin-gui/src/main/resources/initial-objects/120-security-policy.xml">https://github.com/Evolveum/midpoint/blob/master/gui/admin-gui/src/main/resources/initial-objects/120-security-policy.xml</a><br>
<br>
Regards,<br>
Ivan<br>
<br>
<div class="moz-cite-prefix">On 04/19/2016 10:49 AM, Aivo Kuhlberg
wrote:<br>
</div>
<blockquote cite="mid:1461055786690.34253@rmit.ee" type="cite">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none"><!--P{margin-top:0;margin-bottom:0;} --></style>
<p>When user types his/her password wrong 3 times then there
appears message "User is locked, please wait." What does that
message mean? Will the user be automatically unlocked after some
period or does admin user has to unlock the user?<br>
Another question is where can admin user see if the user is
locked or not? Is there possible to change lockout settings
(number of tries after account locks or use captcha after number
of wrong tries)<br>
I am using midPoint 3.3.1<br>
<br>
</p>
<p>Thanks,</p>
<p>Aivo Kuhlberg<br>
</p>
<br>
<hr>
<font face="Arial" color="Gray" size="2">Käesolev e-kiri võib
sisaldada asutusesiseseks kasutamiseks tunnistatud teavet.<br>
This e-mail may contain information which is classified for
official use.</font>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
midPoint mailing list
<a class="moz-txt-link-abbreviated" href="mailto:midPoint@lists.evolveum.com">midPoint@lists.evolveum.com</a>
<a class="moz-txt-link-freetext" href="http://lists.evolveum.com/mailman/listinfo/midpoint">http://lists.evolveum.com/mailman/listinfo/midpoint</a>
</pre>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
Ing. Ivan Noris
Senior Identity Management Engineer & IDM Architect
evolveum.com evolveum.com/blog/
___________________________________________________
"Semper ID(e)M Vix."
</pre>
</body>
</html>