Does Redmine have a feature that automatically locks an account after failed login attempts?
Redmine does not have a feature that automatically locks an account based on the number of failed login attempts.
In general, an account lock feature based on failed logins has a weakness. A malicious third party can repeat failed attempts with a specific user ID. In this way, the third party can intentionally prevent the legitimate user from logging in (a denial-of-service attack).
Measures to prevent unauthorized logins
To prevent unauthorized logins caused by guessed or leaked passwords, we recommend that you require two-factor authentication for all users.
Redmine supports two-factor authentication. When you make two-factor authentication required, an unauthorized login becomes very difficult in practice even if a password is leaked. The attacker must also obtain the one-time password that is shown on a device that the user owns, such as a smartphone.
