<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00005zRobRSASOkta Classic EngineAdministrationAnswered2019-02-20T23:05:37.000Z2019-02-20T19:56:05.000Z2019-02-20T23:05:37.000Z

PaulA.08356 (Customer) asked a question.

protect authorization server(s) from DoS?

hello Okta Support:

 

I'm fully versed in OAuth2, OIDC etc.. My question here related precisely and only to this scenario below:

 

suppose a bad actor creates an app that floods one/all of my Okta token-validation servers with random (and therefore obviously) invalid tokens.

 

Since you don't know what's an invalid token without the server at least *seeing* that token, you have to at least accept the request before you can inspect/discard the token.

 

Does Enterprise Okta allow admins to create & maintain firewall rules so that abusive IP addresses can be blocked, and relieve the server from having to look at the validation requests?


This question is closed.
Loading
protect authorization server(s) from DoS?