Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

Case Insensitive Logins with RQM

In order that case insensitive logins can be used with RQM, I have switched the option 'Use case insensitive user ID matching' to 'true' within the 'Advanced Properties' section of the Jazz Team Server.

The behaviour now being seen is that when I log in using mixed case, I seem to be logged in as the user 'ADMIN' rather than myself. There is not a problem if I use lower case logins.

Can anyone explain this behaviour to me?

I have RQM 3.0.1 installed and using OpenLDAP.

0 votes



4 answers

Permanent link
This is managed by jazz foundation. You would like to check this in foundation forum

0 votes


Permanent link
I encountered this issue with RTC 4.0.0.1 but couldnt figure out the reason behind this behaviour.

If the user belongs to JazzAdmin group, case insensitive username allow user to login as ADMIN user(which I disabled during JTS setup). If the user is a member of JazzUser group he/she cant login to jazzteamserver.

Why is this happening?

0 votes


Permanent link
Are you able to login to jts/admin page with mixed case?
If so, make sure that you update  'Use case insensitive user ID matching' to 'true' in the 'Advanced Properties' section on RQM admin page too.

0 votes

Comments
Yes I am able to login but what's the purpose of this usage? why am I logged-in as ADMIN when I use mixed case? Is this something implemented for security or some other purpose? Who would want to login as ADMIN user(I disabled it during jts setup)? One of my client claims that it is a bug. Am I trying to understand this.


Permanent link

Hello,

if you are able to login with your user name but you see ADMIN as logged in user in the upper right corner that means that the application server found the user in LDAP but the user is not found in the application, in your case in QM.

This works only for jazzadmins that way. A none jazzadmin user would not be able to login but a jazzadmin has to be able to login even he is not added to the application yet.

There maybe different reasons why the user is not found in the application:
- user is not imported from LDAP
- the application is not set to case insensitive
- LDAP is not configured correctly for this application

Hope this makes sense.

Elisabeth

0 votes

Comments
Wouldn't it cause a lack of security in case someone with an mixed case id logs into jazz team server and change some configuration? We haven't tried to change any configuration while logged in with this user but I think it's possible. If we are able to audit this change we'll see ADMIN user in the logs. That's my customers perspective.

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details

Question asked: Mar 08 '12, 5:47 a.m.

Question was seen: 6,710 times

Last updated: Apr 08 '13, 9:33 a.m.

Confirmation Cancel Confirm