Actions
Bug #26847
openBrute-force protection being triggered using haproxy
Status:
New
Priority:
Normal
Assignee:
-
Category:
Authentication
Target version:
-
Description
When using a haproxy in front of Foreman, the IP that is being checked in failed logins is the one for haproxy. So 30 authentications in 5 minutes coming from the same haproxy blocks all the logins coming from that haproxy.
Should it use request.remote_ip instead of request.ip to make it work with X-Forwarded-For headers?
Actions