It's all about the answers!

Ask a question

Case Insensitive Logins with RQM


Rizwan Shamim (1644) | asked Mar 08 '12, 5:47 a.m.
In order that case insensitive logins can be used with RQM, I have switched the option 'Use case insensitive user ID matching' to 'true' within the 'Advanced Properties' section of the Jazz Team Server.

The behaviour now being seen is that when I log in using mixed case, I seem to be logged in as the user 'ADMIN' rather than myself. There is not a problem if I use lower case logins.

Can anyone explain this behaviour to me?

I have RQM 3.0.1 installed and using OpenLDAP.

4 answers



permanent link
Pramod Chandoria (2.1k11220) | answered Mar 09 '12, 7:20 a.m.
JAZZ DEVELOPER
This is managed by jazz foundation. You would like to check this in foundation forum

permanent link
Canberk Akduygu (99237371) | answered Apr 08 '13, 6:09 a.m.
I encountered this issue with RTC 4.0.0.1 but couldnt figure out the reason behind this behaviour.

If the user belongs to JazzAdmin group, case insensitive username allow user to login as ADMIN user(which I disabled during JTS setup). If the user is a member of JazzUser group he/she cant login to jazzteamserver.

Why is this happening?

permanent link
Vidya Malkarnekar (1.0k15) | answered Apr 08 '13, 7:42 a.m.
JAZZ DEVELOPER
Are you able to login to jts/admin page with mixed case?
If so, make sure that you update  'Use case insensitive user ID matching' to 'true' in the 'Advanced Properties' section on RQM admin page too.

Comments
Canberk Akduygu commented Apr 08 '13, 8:50 a.m.

Yes I am able to login but what's the purpose of this usage? why am I logged-in as ADMIN when I use mixed case?

Is this something implemented for security or some other purpose? Who would want to login as ADMIN user(I disabled it during jts setup)?

One of my client claims that it is a bug. Am I trying to understand this.


permanent link
Elisabeth Carbone (616108) | answered Apr 08 '13, 9:14 a.m.
JAZZ DEVELOPER

Hello,

if you are able to login with your user name but you see ADMIN as logged in user in the upper right corner that means that the application server found the user in LDAP but the user is not found in the application, in your case in QM.

This works only for jazzadmins that way. A none jazzadmin user would not be able to login but a jazzadmin has to be able to login even he is not added to the application yet.

There maybe different reasons why the user is not found in the application:
- user is not imported from LDAP
- the application is not set to case insensitive
- LDAP is not configured correctly for this application

Hope this makes sense.

Elisabeth


Comments
Canberk Akduygu commented Apr 08 '13, 9:33 a.m.

Wouldn't it cause a lack of security in case someone with an mixed case id logs into jazz team server and change some configuration? We haven't tried to change any configuration while logged in with this user but I think it's possible.

If we are able to audit this change we'll see ADMIN user in the logs.

That's my customers perspective.

Your answer


Register or to post your answer.


Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.