# Keycloak temporary lockout algorithm - clarification

**URL:** <https://forum.keycloak.org/t/keycloak-temporary-lockout-algorithm-clarification/7238>\
**Category:** Miscellanaeous\
**Created:** [February 8, 2021, 5:45am UTC](https://forum.keycloak.org/t/keycloak-temporary-lockout-algorithm-clarification/7238 "2021-02-08T05:45:11Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![kharim](https://avatars.discourse-cdn.com/v4/letter/k/839c29/32.png) [@kharim](https://forum.keycloak.org/u/kharim)\
**Post date:** [February 8, 2021, 5:45am UTC](https://forum.keycloak.org/t/keycloak-temporary-lockout-algorithm-clarification/7238/1 "2021-02-08T05:45:11Z")

</div>

Hi, I am not able to understand the temporary lockout algorithm. i copied the confusing part below. my questions are the following  
q1) is the step to disable a sub step of step 4 below? i.e. disable only if wait is 0 and too fast attempt?  
q2) Does it mean disable only if user has two login failures within the quick login check milliseconds?  
q3) wait will not be 0 after count becoming aleast half of max login failures, rounding will happen to 1. does it mean after that, there is never a disable? because wati will never be 0 after that?

1. Calculate `wait` using _Wait Increment_ \* ( `count` / _Max Login Failures_ ). The division is an integer division so will always be rounded down to a whole number
2. If `wait` equals 0 and time between this failure and the last failure is less than _Quick Login Check Milli Seconds_ then set `wait` to _Minimum Quick Login Wait_ instead  
1. Temporarily disable the user for the smaller of `wait` and _Max Wait_ seconds
