Oracle Access Manager 11gr2ps2 (OAM 11.1.2.2.0) Oblogintrycount is not Reset After Lockout Period/Duration
(Doc ID 2268826.1)
Last updated on NOVEMBER 09, 2023
Applies to:
Oracle Access Manager - Version 11.1.2.0.0 and laterInformation in this document applies to any platform.
Symptoms
Oracle Access Manager 11gr2ps2 (OAM 11.1.2.2.0) Oblogintrycount is not Reset After Lockout Period/Duration
- The oblogintrycount value keeps incrementing after the lockout period has expired.
- In the test case, a user that has failed authentication 3 times and is locked out for 1 hour. This is working properly. We are expecting OAM to allow another 3 authentication attempts after the lockout period is over. However, after the lockout period is over, if the user attempts another bad authentication (while oblogintrycount still equals 3) the oblogintrycount is being incremented to 4 and the user is locked out for another hour (oblockouttime and oblastfailedlogin are updated).
- Our DCC authentication scheme is set to "OverrideRetryLimit=1" and our password policy contains max attempts=3 and lockout duration=60min.
- OAM version: 11.1.2.3.170418
- OS: Oracle Linux 6 (virtual) on Exalogic
- Webgate: 11.1.2.3.170418 on Apache 2.4.6 (Oracle Linux 7)
- DB: 12.1.0.2 on Exadata
- Directory: OUD - 11.1.2.3.170418
- OAM BUNDLE PATCH 11.1.2.3.170418
Native password policy
-Maximum Attempts: 3
-LockoutDuration (minutes): 5
Before Lock:
oblastfailedlogin: 2017-05-11T14:14:17Z
oblastsuccessfullogin: 2016-05-11T14:04:44Z
obpasswordchangeflag: false
After Lock:
oblastfailedlogin: 2017-05-11T16:26:24Z
oblastsuccessfullogin: 2016-05-11T14:04:44Z
oblockouttime: 1494545484 ------------------------------> GMT: Thu, 11 May 2017 23:31:24 GMT
oblogintrycount: 3
obpasswordchangeflag: false
AfterLockoutTime:
oblastfailedlogin: 2017-05-11T16:34:05Z
oblastsuccessfullogin: 2016-05-11T14:04:44Z
oblockouttime: 1494545945 -------------------------------> GMT: Thu, 11 May 2017 23:39:05 GMT
oblogintrycount: 4
obpasswordchangeflag: false
obpasswordexpirydate: 2017-08-11T00:57:47Z
Changes
Cause
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Symptoms |
Changes |
Cause |
Solution |
References |