Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

LDAP users being used and getting messages re: abuse from LDAP admins

Ok.

This just started happening at TWO separate locations (Rome, RTP).  Users report that the LDAP authentication is somehow using an ID and passing the incorrect password (1000s of times).  The first such was a 'service' ID which I could understand as it *might* have been configured into a friend connection.  However, a user came by my office today with the same issue.

Checking with user regarding automation.   But the suddenness and coincident occurrences lead me to post here.

Side question:  is there a log4j property that can be set to record failed login attempts?  Our WebSphere app servers report it something like this:

[12/6/12 2:50:19:510 EST] 00000013 FormLoginExte E   SECJ0118E: Authentication error during authentication for user ovidiu
[12/6/12 4:23:05:246 EST] 00000021 FormLoginExte E   SECJ0118E: Authentication error during authentication for user Adrian.O
[12/6/12 5:42:33:290 EST] 000000b7 FormLoginExte E   SECJ0118E: Authentication error during authentication for user Adrian.O
[12/6/12 5:42:34:151 EST] 00000019 FormLoginExte E   SECJ0118E: Authentication error during authentication for user Adrian.O


0 votes

Comments

Ok, user issue traced to automation.  Still searching for the source of the 'automation' id login failures.



One answer

Permanent link
Hi Kevin,

What version of JTS do you used? I came across a similar problem in version 3.0.1.1, as datawarehouse user need exist in LDAP, I use a normal user (insteads of) non-expiring password functional user id. As normal user need to change his/her password after a fixed period of time, that get forgotten.

So you will need to make these changes in the three applications, /jts, /ccm and /qm.

Here is the url form
https://<host>:<port>/<app>/admin#action=jazz.viewPage&id=com.ibm.team.reports.reportsManagementPage

I have noticed that in version 3.0.1.4 onwards, if if you left etl_user blank, and OAuth is used instead.

Hope this helps.

0 votes

Comments

Thanks I will keep this in mind.  The owner of the service ID has reset the password and it the ID is logging in successfully so far.

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details
× 88

Question asked: Dec 06 '12, 10:19 a.m.

Question was seen: 6,967 times

Last updated: Dec 07 '12, 2:52 p.m.

Confirmation Cancel Confirm