IBM Support

IBM Rational ClearQuest accepts LDAP authentication with previous password

Troubleshooting


Problem

ClearQuest accepts to connect with the current password but also with the previous used password when authenticating through LDAP.

Symptom

When you configure ClearQuest to authenticate through LDAP, users could authenticate with a current and previous password for some time. This behavior continues for about an hour. Then the system no longer accepts the old password.


Steps to reproduce


  1. Login as User1

  2. Enter an e-mail ID.

  3. Enter the password.


  4. Do a CQ LDAP mapping on the e-mail ID.

  5. Connect to ClearQuest with the e-mail ID and Passw0rd1. This works as expected.


  6. Change Windows account password to Passw0rd2.


  7. Immediately, change again the Windows password to Passw0rd3


  8. Run the folowing command from the command line to test that new password is taken into account


    runas /user:domain\User1 calc
    with Passw0rd3. The application runs successfully.


    Run the folowing command from the command line to test that old password is invalid.


    runas /user:domain\User1 calc
    with Passw0rd2 .

    You see the following error:


    invalid user name or password is incorrect



  9. Start ClearQuest* with Passw0rd3 and see that you connect successfully.


  10. Note that until now, ClearQuest does not know the previous password (2) and connection succeeds with the new current password (3).

  11. Then start ClearQuest* with Passw0rd2. You connect successfully!

[{"Product":{"code":"SSSH5A","label":"Rational ClearQuest"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":"User Administration - LDAP","Platform":[{"code":"PF033","label":"Windows"}],"Version":"7.1.1;7.1.1.7;7.1.1.6;7.1.1.5;7.1.1.4;7.1.1.3;7.1.1.2;7.1.1.1;7.1.2;7.1.2.1;7.1.2.2;7.1.2.3;7.1.2.4;7.1.2.5;7.1.2.6;8.0;8.0.0.1;8.0.0.2","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
16 June 2018

UID

swg21599831