Hi,
I'm having a problem where a user's account it's being locked because of multiple failed login attempts. What I have done in other systems is to rename the user to something else, and create an alias with the old email address. This way, the attacker trying to brute-force the password guessing using the email alias will never succeed. The problem with Zimbra is that the system accepts the user password even if using the aliases as username. Is there a way to disable this behavior? Any other suggestion in mind?
Thank you in advance
Antonio
Protect email account with alias
-
- Posts: 1
- Joined: Thu Aug 18, 2022 8:03 pm
Re: Protect email account with alias
Hi Antonio,
We found that the following worked to disable alias logins.
Hope it works for you.
We found that the following worked to disable alias logins.
Code: Select all
zmlocalconfig -e alias_login_enabled=false