Authentication Attempt Rate Limiting
Authentication Attempt Rate Limiting
Authentication attempt rate limiting provides additional protection against repeated failed authentication attempts.
Configure Authentication Attempt Rate Limiting
Configure authentication attempt rate limiting in the nexus.properties file.
nexus.auth.ratelimit.enabled=true
nexus.auth.ratelimit.max-attempts=3
nexus.auth.ratelimit.base-delay-seconds=30
nexus.auth.ratelimit.max-delay-seconds=900
nexus.auth.ratelimit.max-tracked-keys=10000
After updating these properties, restart Nexus Repository.
Configuration Properties
The following properties are available for authentication attempt rate limiting:
| Property | Description | Default | Valid values |
|---|---|---|---|
nexus.auth.ratelimit.enabled |
Enables or disables authentication attempt rate limiting. Set to false to disable rate limiting. |
true |
true or false |
nexus.auth.ratelimit.max-attempts |
Number of consecutive failed authentication attempts before rate limiting is applied. | 3 |
Positive values |
nexus.auth.ratelimit.base-delay-seconds |
Base delay, in seconds, used when calculating the rate-limit timeout. | 30 |
Positive values |
nexus.auth.ratelimit.max-delay-seconds |
Maximum delay, in seconds, that can be applied by rate limiting. | 900 |
Positive values |
nexus.auth.ratelimit.max-tracked-keys |
Maximum number of unique users or tokens the rate limiter tracks simultaneously in memory. | 10000 |
Positive values |
Authentication Scope
Authentication attempt rate limiting applies to:
- HTTP Basic authentication
- Token-based authentication
For SAML/SSO authentication, authentication is handled by the identity provider (IdP). Authentication attempt rate limiting does not apply to the SAML/SSO login process.
Rate-Limit Response
When authentication attempts are rate limited, Nexus Repository returns HTTP status code 429 Too Many Requests.
The response includes a Retry-After header.
Example Configuration and Behavior
Example configuration:
nexus.auth.ratelimit.max-attempts=5
nexus.auth.ratelimit.base-delay-seconds=30
nexus.auth.ratelimit.max-delay-seconds=3600
For a user with repeated failed authentication attempts:
| Attempt | Result | Retry Delay |
|---|---|---|
| 1–5 | Allowed | - |
| 6 | Blocked | 30 seconds |
| 7 | Blocked | 60 seconds |
| 8 | Blocked | 120 seconds |
| 9 | Blocked | 240 seconds |
| 10 | Blocked | 480 seconds |
| … | … | … |
| 18+ | Blocked | 3600 seconds |
- Each blocked attempt increments the failure counter.
- A successful authentication clears the counter immediately.
- In clustered deployments, each node maintains an independent rate-limit state.
Monitoring
Authentication attempt rate limiting events are recorded in the audit log under the following domain:
security.auth.ratelimit
High Availability Deployments
Authentication attempt rate limiting state is maintained in memory and is not shared across cluster members.
Note
Use positive values for authentication attempt rate limiting configuration properties.