632 mentions we could delegate authentifcation to an LDAP server. Or to something else. Such a verification policy should thus be handled by these delegates, and not by Roboconf directly.
This will have to be mentioned in the documentation.
This is the reason why this issue is kept open for the moment.
Following #632, can we limit the number of times one can attempt to login? How can we specify a delay before two unsuccessful attempts?