Comment 13 for bug 1688137

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Attacker may use PCI-DSS 8.1.6 and 8.1.7 to lock out users indefinitely

It seems like this warrants an advisory (class A according to VMT's taxonomy: https://security.openstack.org/vmt-process.html#incident-report-taxonomy).

@keystone-coresec, please review proposed patch in comment #12.

Is there a documented manual procedure to unlock accounts?