More Security
More Security protects the GLPI login page and the "forgotten password" form against automated password-guessing attacks.
1. Introduction
Part of the More Security manual — see also 2. What's New, 3. Scope, 4. Setup, 5. Usage, 6. Troubleshooting.
1.1 What More Security does
More Security protects the GLPI login page and the "forgotten password" form against automated password-guessing attacks. If someone — or some script — keeps trying wrong passwords against an account, or keeps requesting password resets, More Security notices and temporarily locks that account, that email address, or the attacker's network address, so the attack simply stops working. It also supports geoblocking: restricting logins to specific countries or blocking entire regions based on where the client's IP address is located.
1.2 Pain points it addresses
Login pages on the public internet are attacked constantly. Without protection, an attacker can sit and guess passwords or spam the "forgotten password" form for as long as they like, and GLPI itself won't stop them — it has no built-in defense against this. That's a real risk: a compromised account can mean exposed tickets, assets, and client data. More Security closes that gap: it slows attackers to a crawl and locks out repeated failures automatically, with no ongoing effort from IT staff, and no change to how legitimate users log in.
1.3 Features
- Locks an account after too many wrong password attempts, for a duration you choose — or until an administrator manually unlocks it
- Automatically forgets old failed attempts after a quiet period, so a genuine user who mistypes their password once isn't punished
- Blocks a single network address after too many failed attempts, whether it's guessing one account or many — stopping a broad attack even if it never fully locks one account
- Recognises a coordinated attack that spreads guesses across many different addresses to avoid triggering the usual limits, and locks the targeted account anyway
- Understands when GLPI sits behind a company firewall or load balancer, so the real attacker's address is blocked — not the office's shared address
- Lets you mark trusted networks (like your own office) as exempt from blocking, so staff working from a known location are never accidentally locked out
- Restricts logins to specific countries or blocks entire regions, using the client IP's geographic location for access control
- Keeps a read-only log of every login/reset attempt for security auditing
- Displays attack trends on the Central dashboard: the top attacking IP addresses and most-targeted user accounts, broken down by time range (24 hours, 7 days, 30 days)
Generated for More Security 2.0.0 on GLPI 11.0.8 — 2026-08-24.
2. What's New
Part of the More Security manual — see also 1. Introduction, 3. Scope, 4. Setup, 5. Usage, 6. Troubleshooting.
Unreleased
2.0.0 - 24/08/2026
New
- Geoblocking support: block or allow logins based on the country the client IP resolves to — disabled by default, with separate allow-list and block-list modes
- Redesigned configuration page with stacked cards — IP blocking, Whitelisting, and Geoblocking are now visually grouped and easier to navigate
- IP whitelist configuration via web UI — enter comma-separated CIDR ranges directly in the config form instead of database-only setup
- Security log now shows individual attempts by default — expanded detail view with separate columns for Login, Email, and User to identify attack patterns more clearly
- Dashboard cards now track attack trends accurately — top attacking IPs and most-targeted accounts use the per-attempt log for real-time counts across 24h, 7-day, and 30-day ranges
Fixed
- Security log page no longer crashes when opening the "Type" search filter
- Security log tabs no longer reset to the default when sorting, filtering, or paginating
- Dashboard layout and colors tuned to match the reference design
Generated for More Security 2.0.0 on GLPI 11.0.8 — 2026-08-24.
3. Scope
Part of the More Security manual — see also 1. Introduction, 2. What's New, 4. Setup, 5. Usage, 6. Troubleshooting.
Reference only — see 4. Setup for how to configure each of these.
3.1 Assets, management & administration items
- The Setup > General configuration screen gains a new "More Security" section for all of the above settings
- The Central dashboard includes a new "More Security" dashboard with attack-trend cards
- The admin menu gains a new Security log item for searching and auditing attempt history
- User profiles gain a new permission that controls who can view the security log
- Nothing else in GLPI is modified — all data the plugin needs lives in its own tables
3.2 Automatic actions
- Monthly automatic update of the GeoIP database for geoblocking
- Weekly automatic cleanup of old, resolved security-log entries
A scheduled task runs automatically (once a month) to download the latest DB-IP Lite database, keeping geoblocking country data current.
Another scheduled task runs automatically (roughly once a week, overnight) to clean up old, resolved entries from the security log, so the log doesn't grow forever. Only entries that are no longer blocking anyone are removed; anything still actively blocked — including a permanent block — is kept. How long an entry is kept before cleanup is configurable from Setup > Automatic actions.
Actually blocking and unblocking happens instantly when an attempt occurs — only the log cleanup and database updates run on a schedule.
See 4.2 Configuration.
3.3 Notifications
None — no emails are sent. A blocked user simply sees an error message on the login or password-reset page itself, right when they try again.
3.4 Rules
Not applicable — no GLPI rules engine integration.
3.5 Permissions
- Changing the More Security settings requires the same permission as changing any other general GLPI setting — no separate right to manage.
- Viewing the security log is controlled by its own dedicated permission, which can be given to specific profiles independently of other rights. This log is read-only for everyone: even a profile with full rights can view entries but never edit or delete them.
- The trusted-network whitelist is configured alongside other settings in the More Security configuration tab, using the same permission as other general GLPI settings.
See 4.3 Permissions.
Generated for More Security 2.0.0 on GLPI 11.0.8 — 2026-08-24.
4. Setup
Part of the More Security manual — see also 1. Introduction, 2. What's New, 3. Scope, 5. Usage, 6. Troubleshooting.
4.1 Installation
Install like any GLPI plugin: from the GLPI Marketplace, or by downloading it and installing/activating it from Setup > Plugins.
4.2 Configuration
Configuration lives entirely on the More Security tab of Setup > General — no separate setup wizard. See the manual's 3. Usage chapter for the full walkthrough with screenshots.
4.2.1 Automatic actions
- Monthly automatic update of the GeoIP database for geoblocking
- Weekly automatic cleanup of old, resolved security-log entries
A scheduled task runs automatically (once a month) to download the latest DB-IP Lite database, keeping geoblocking country data current.
Another scheduled task runs automatically (roughly once a week, overnight) to clean up old, resolved entries from the security log, so the log doesn't grow forever. Only entries that are no longer blocking anyone are removed; anything still actively blocked — including a permanent block — is kept. How long an entry is kept before cleanup is configurable from Setup > Automatic actions.
Actually blocking and unblocking happens instantly when an attempt occurs — only the log cleanup and database updates run on a schedule.
4.3 Permissions
- Changing the More Security settings requires the same permission as changing any other general GLPI setting — no separate right to manage.
- Viewing the security log is controlled by its own dedicated permission, which can be given to specific profiles independently of other rights. This log is read-only for everyone: even a profile with full rights can view entries but never edit or delete them.
- The trusted-network whitelist is configured alongside other settings in the More Security configuration tab, using the same permission as other general GLPI settings.
4.4 Configuring More Security
The More Security plugin provides brute-force protection for login and password-reset attempts, with per-account and per-IP throttling. All configuration is done through one tab in Setup > General.
4.4.1 Open the More Security configuration
From GLPI's main menu, navigate to Setup > General and click the More Security tab to access the plugin's configuration interface.
The More Security tab shows all protection settings organized into sections for IP blocking, Login attempts, and Password reset.
Note: All configuration changes take effect immediately without requiring a page reload or GLPI restart.
4.4.2 Configure login attempt blocking
The Login attempts section defines how many failed logins trigger a temporary account block, and how long that block lasts. In this example: after 5 failed attempts, the account is locked for 300 seconds.
Login attempts are configured to block accounts after 5 failed login attempts, for 300 seconds.
4.4.3 Set password reset attempt limits
The Password reset section prevents unauthorized account takeover through reset-link brute-forcing, with its own independent attempt limit and block duration. In this example: after 3 failed reset attempts, access is locked for 600 seconds.
Password reset is limited to 3 attempts per 600 seconds to prevent reset-link abuse.
4.4.4 Configure IP-based blocking and trusted proxies
The IP blocking section throttles abuse by source IP — shared across login and password-reset attempts — independent of the per-account limits above, plus distributed-attack detection and trusted reverse-proxy IPs.
The IP blocking section configures per-IP attempt limits, distributed-attack detection, and trusted reverse-proxy IPs.
4.4.5 Review currently blocked accounts
Below the configuration fields, the Active blocks table lists every account, IP, or email currently locked, with the attempt count and remaining block time. Individual rows (or a selection) can be unlocked early. In this example, the account testuser shows as temporarily blocked.
The Active blocks table shows every currently locked account, IP, or email, with its expiration and an Unlock action.
4.4.6 Configure the IP whitelist and trusted proxies
The Whitelisting section exempts trusted networks from IP-based blocking entirely, and separately lists reverse proxies whose own IP should be ignored in favour of the forwarded client address. Whitelisted IPs/CIDR ranges accepts one or more comma-separated CIDR ranges (e.g. 192.0.2.0/24) or single addresses — any login or password-reset attempt from a whitelisted address bypasses all IP-based limits and geoblocking. In this example: 192.0.2.0/24 is whitelisted.
The Whitelisting section exempts 192.0.2.0/24 from IP-based blocking and geoblocking.
4.4.7 Configure geoblocking by country
The Geoblocking section restricts logins by the country the client IP resolves to: disabled, allow-list only, or block-list. Whitelisted IPs and unresolvable IPs (private/local, or a missing database) always bypass this check.
The Geoblocking section sets the allow/deny mode and the country list it applies to, with the DB-IP data attribution.
Note: Geoblocking country data comes from DB-IP's free Lite database, refreshed automatically once a month.
Generated for More Security 2.0.0 on GLPI 11.0.8 — 2026-08-24.
5. Usage
Part of the More Security manual — see also 1. Introduction, 2. What's New, 3. Scope, 4. Setup, 6. Troubleshooting.
5.1 Monitoring attacks with dashboard cards
More Security provides six dashboard cards showing attack trends: the top attacking IP addresses and the most-targeted accounts, each available for three time ranges (last 24 hours, last 7 days, last 30 days).
5.1.1 Open the Central dashboard
From GLPI's main menu, navigate to Central. The dashboard displays the configured dashboard layout, which includes the More Security cards if the More Security dashboard is active. The dashboard contains six cards arranged in rows, showing attack metrics for 24-hour, 7-day, and 30-day time ranges.
The Central page displays the More Security dashboard with cards showing the top attacking IP addresses and most-targeted accounts across different time ranges.
Note: The More Security dashboard is created automatically when the plugin is installed. Each card displays the top sources or targets in that time window (24 hours, 7 days, or 30 days). Click any entry to filter the Security log to that specific source IP or target account.
5.2 Reviewing login and password-reset attempts in the security log
More Security keeps a complete, read-only log of every login and password-reset attempt. Administrators can search, filter, and investigate this log to respond to security incidents.
5.2.1 Navigate to the Security log menu
From GLPI's main menu, navigate to Admin > Security log. The security log is a searchable, read-only list displaying every login attempt, password-reset request, and IP-based activity tracked by the plugin.
The Security log page displays a searchable table of all login attempts, password-reset requests, and IP-based attacks, with columns for Event type, target Identifier/IP, Attempt count, and Block status.
Note: The log tracks five event types: Login (failed attempts against an account), Login IP (IP-based login tracking), Login (geoblocked) (a login refused because of the client's country — for this event type the log shows the resolved country code, e.g. RU, KP, CN, in place of an IP), Password reset email (failed password reset attempts), and Password reset IP (IP-based password reset tracking). Use the search interface to filter by Event type, IP address, Username/Email, Status (Blocked/Unlocked/Not blocked), or date range to investigate attacks. Click any entry to view full details. The log is read-only; to manually unlock a blocked account or IP, use the Active Blocks table in the More Security configuration instead.
Generated for More Security 2.0.0 on GLPI 11.0.8 — 2026-08-24.
6. Troubleshooting
Part of the More Security manual — see also 1. Introduction, 2. What's New, 3. Scope, 4. Setup, 5. Usage.
Troubleshooting
Accounts or IPs become stuck blocked
Check the More Security tab on Setup > General. If an account or IP is still listed under "Active blocks" but should no longer be blocked, use the "Unblock" button next to the entry or select multiple entries and use "Unlock selected" to clear them.
The temporary block duration depends on the configuration:
- Login account blocks expire after the "Login block duration" setting (default 5 minutes)
- Password reset blocks expire after the "Password reset block duration" setting (default 10 minutes)
- IP blocks expire after the "IP block duration" setting (default 15 minutes)
Permanent blocks (marked "Permanent" instead of a time duration) never expire automatically and require manual unblock.
Legitimate users getting blocked
If regular users report login failures or repeated password reset rejections, check:
-
Configuration — Review the attempt limits on the More Security tab:
- "Number of login attempts before block" — lower values block faster
- "Number of password reset attempts before block" — separate limit for password resets
- "Attempts counting window" — the time period over which attempts are counted
-
Shared IP addresses — If multiple users share a single IP (corporate office, hosting provider, school network), the per-IP limit "Number of attempts before IP block" may block the entire group after a few combined failed attempts. Check the "Active blocks" section to see if the IP is blocked, and use "Unblock" if needed. Configure "Trusted proxies" if users connect through reverse proxies or load balancers.
-
Password reset abuse — Users sometimes trigger many failed password-reset attempts while trying to recover a forgotten password. This is independent of login blocking — check the "Password reset block duration" and attempt limits separately.
Cannot access the More Security configuration
The More Security tab on Setup > General requires the same permission as any other general GLPI setting. If a user can't see the tab, check with an administrator that their profile has permission to edit general setup.
IP whitelist entries
A whitelisted network address is never blocked, no matter how many failed attempts come from it — useful for a trusted office network or monitoring service. CIDR notation (e.g. 203.0.113.0/24) is supported for whitelisting an entire range at once.
At the moment, there is no page in GLPI where an administrator can add or remove whitelist entries themselves — this needs to be set up by your technical support/development contact. If you need a new address whitelisted, ask them directly rather than looking for it on the More Security tab.
The full attempts log appears empty
A more detailed "Attempts" table (visible to administrators with GLPI's debug mode turned on) shows every login/password-reset attempt, including failed ones that haven't triggered a block yet. If it appears empty:
- Trigger an attempt — have someone try to log in or reset their password to generate test data
- Check filters — the table may have filters applied; clear them to see all attempts
- Verify the plugin is active — if the plugin was recently updated or restarted, the table may not appear until GLPI's cache is cleared
Blocked accounts shown with missing display names
The "Active blocks" table shows the account login, email, and IP. If the login field contains only a username with no full name or profile link, the account exists but may have been deleted since the block was created. The block record itself persists until manually unblocked or the temporary duration expires.
Geoblocking doesn't seem to be blocking anything
Geoblocking relies on a downloaded country database (DB-IP Lite) that must be fetched by the plugin's "update GeoIP database" automatic action before geoblocking can work. If that action hasn't run yet (e.g. right after install, or on a fresh environment), the database file won't exist and geoblocking fails open — logins are allowed through regardless of country, rather than being blocked.
To check:
- Run the automatic action — go to Setup > Automatic actions, find the GeoIP database update task for More Security, and run it manually (or wait for its normal schedule).
- Check GLPI's Events log — a failed lookup due to a missing or corrupt database logs an entry there ("GeoIP lookup failed ... database unavailable"). If you see this, the database hasn't downloaded successfully.
- Confirm outbound network access — the automatic action downloads from db-ip.com; if the server has no outbound internet access or is behind a restrictive proxy/firewall, the download will keep failing silently until network access is fixed.
Until the database is present, treat geoblocking as effectively disabled — no logins will be rejected on country grounds, even if a mode and country list are configured.
"Too many attempts" error when trying to log in
This means the login or password-reset request was rejected because the account, address, or email hit its attempt limit — technically shown as an HTTP 429 error if you check your browser's network tools. This is expected: the protection is working as intended. Wait for the block duration to expire (default: 5 minutes for login, 10 minutes for password reset) or ask an administrator to unblock it early from the More Security tab.
Generated for More Security 2.0.0 on GLPI 11.0.8 — 2026-08-24.