My Oracle Support Banner

OAM 11g: When Incorrect Password Attempts Exceed DefaultRetryLimit, OAM Redirects to "Failure URL" (Doc ID 1571525.1)

Last updated on OCTOBER 10, 2023

Applies to:

Oracle Access Manager - Version 11.1.2.0.0 and later
Information in this document applies to any platform.

Goal

 

After login attempts with incorrect password exceeds DefaultRetryLimit configured in oam-config,xml, should OAM redirect to "Failure URL" configured in Protected Resource Policy or the "Password Service URL" in the Password Policy ?



Setup
  1. Authentication Protected Resource Policy is configured with "Failure URL".
  2. Protected Resource Policy is configured to use PasswordPolicyValidationScheme
  3. PasswordPolicyValidationScheme uses "Password Policy Validation Module" which invokes UserPasswordPolicyPlugin in UserPasswodStatus Step.
  4. Password Service URL is as "/oam/pages/pswd.jsp" (Default)
  5. oam-config.xml file has DefaultRetryLimit set to 5
  6. max attempts is password policy is set to 5 as well.



 

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.