Skip to main content
Declined

Secure login via CAPTCHA

Related products:Infra Monitoring - Global/Installation
  • September 28, 2022
  • 4 replies
  • 50 views

Arnaud
Forum|alt.badge.img+3

This is a very simple idea :

Local et AD authentication need to have a CAPTCHA for secure Centreon login from bot attacks. 

This not concerne OpenID authentication because providers have some secure process.

 

4 replies

fgbetokpanou
Centreonian
Forum|alt.badge.img+11
  • Centreonian
  • September 28, 2022

Hi @Arnaud,  Thank you for your idea proposal. I would invite you to reformulate it according to the guidelines you can find here. This would help the Product Manager Team to better evaluate your proposal. Thanks for your understanding


lpinsivy
Centreonian
Forum|alt.badge.img+21
  • Centreonian
  • October 3, 2022

Hi @Arnaud, since Centreon 22.04, we have added a secure password policy for the local account which allows to block the user for X minutes if you enter Y wrong password in a row. It's not sufficient ?

Moreover, you can add an identity provider in front of your LDAP to benefit from more security.

Regards,


rchauvel
Centreonian
Forum|alt.badge.img+18
  • Centreonian
  • October 5, 2022
NewDeclined

Arnaud
Forum|alt.badge.img+3
  • Author
  • Steward *
  • October 5, 2022

hi,

I don’t know about secure password policy in 22.04, but if it’s a fail2ban solution, it’s not a good solution.

Because some compagny can use a reverse proxy in front of central.

So Central see the private IP of this proxy and can ban it. In this case, it ban everyone.

maybe you use an other/better solution than fail2ban.

In this case, it’s OK.