##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1:854a839a default
r2128:f22a9ea9 default
Show More
tuning-hg-auth-loop.rst
17 lines | 482 B | text/x-rst | RstLexer
/ docs / admin / tuning-hg-auth-loop.rst

|hg| Authentication Tuning

When using external authentication tools such as LDAP with |hg|, a password retry loop in |hg| can result in users being locked out due to too many failed password attempts. To prevent this from happening, add the following setting to your :file:`/home/{user}/.rccontrol/{instance-id}/rhodecode.ini` file, in the [app:main] section.

[app:main]
auth_ret_code_detection = true