Bug 1245445

Summary: Can't login without user changed password
Product: Red Hat Enterprise Linux 7 Reporter: Jamie Lennox <jlennox>
Component: ipsilonAssignee: Patrick Uiterwijk <puiterwijk>
Status: CLOSED WONTFIX QA Contact: Namita Soman <nsoman>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 7.2CC: nkinder, rcritten, spoore
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-02-16 22:40:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
http error log none

Description Jamie Lennox 2015-07-22 06:09:51 UTC
If as admin I create a new user in FreeIPA when i first login i get asked to change my password. In IPA this works fine, as you get prompted to change, in ipsilon you get the cryptic message: 

401 - Unauthorized

No permission -- see authorization schemes

If ipsilon is unable to do IPA user password changes is there a way we can at least better identify the error?

Comment 2 Rob Crittenden 2015-07-22 12:49:15 UTC
Upstream ticket:
https://fedorahosted.org/ipsilon/ticket/69

Comment 4 Scott Poore 2015-10-14 19:14:10 UTC
Failing this one.  If I connect to the IdP with new user with expired password, I see the new error message. 

However, if I connect to SP, I do not.  I see the same error message from comment #1.

Comment 5 Rob Crittenden 2015-10-14 19:30:09 UTC
Moving to 7.3. This is an enhancement.

I can see the error "Password is expired" on the IdP then it looks like Ipsilon sends back a 303 and the client responds with an empty SAML login request.

Ipsilon then logs "saml2: User is marked anonymous?!" and returns a 401 with the wrong reason.

Re-opened upstream ticket for further work.

Comment 6 Scott Poore 2015-10-14 19:33:47 UTC
Created attachment 1082934 [details]
http error log

Comment 9 Nathan Kinder 2016-02-16 22:40:06 UTC
There are no plans to update Ipsilon in RHEL 7.3, and it is being replaced by Keycloak long-term.  Closing this as WONTFIX.