It's all about the answers!

Ask a question

Restart machine, getting CRJAZ1394E when trying login to JTS, LDAP used


Jin Zhou (591619) | asked Jun 20 '14, 1:40 a.m.
retagged Jul 22 '14, 5:51 p.m. by Ken Tessier (84117)
HI

This is another phenomenon related to JTS+LDAP user authentication.
The tool is normally working fine till we restarted the machine.

We restarted machine and then start Rhapsody DM which is running on Tomcat with LDAP authentication applied.
Users with "JazzUsers" group assigned got below error when trying to login JTS or other Jazz Application page.
>>HTTP Status 403 - CRJAZ1394E The "xxxxx" user ID cannot connect to
>>the repository because it is not assigned to a repository group that
>>has permissions to access the repository.

We checked the user profile in JTS and we could see "JazzUsers" is checked on so we don't understand why the tool still report above error.

Then we tried to restart Tomcat, and found the issue just gone without changing any configuration files.
-------------------------------------------
Do you ever see the similar phenomenon?
What could be the possible cause here?
What could be the differences for restarting machine other than restarting Tomcat server?
When the console mentioned the server is started, does it mean the LDAP group mapping info has been completed read into memory?

Regards


Comments
Donald Nong commented Jun 23 '14, 12:20 a.m.

Is the LDAP server running on the same machine? It is hard to say what might have happen based on the provided information alone. If the issue can be reproduced consistently (e.g. by restarting the machine), you may consider collecting network trace to see what is being passed between the LDAP server and JTS.

One answer



permanent link
Stephanie Bagot (2.1k1513) | answered Jul 15 '14, 2:13 p.m.
FORUM MODERATOR / JAZZ DEVELOPER
The repository groups are controlled by the web.xml in every application. It is possible that this file may not have the correct group mappings for DM - I would recommend looking there if this issue is reproducible.

Comments
Jin Zhou commented Jul 15 '14, 10:07 p.m.

Thanks, Stephanie

I understand this.
The strange thing is all the configuration files related LDAP are correct. There is no changed done on those files before or after restarting machine and RDM.

I don't think RDM would modify the xml files during shutdown.
We tried restart RDM again, thing's getting normal.
So the problematic phenomenon is not consistent.

For the users are failed to login, we still could see the "JazzUsers" are checked from JTS admin page. The true cause to this issue is still unclear.

Regards

Your answer


Register or to post your answer.


Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.