Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1085529 - RHEV-M server appears to send the bad authentication to the AD server repeatedly, locking the account. [NEEDINFO]
RHEV-M server appears to send the bad authentication to the AD server repeate...
Status: CLOSED ERRATA
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: ovirt-engine (Show other bugs)
3.3.0
Unspecified Unspecified
urgent Severity urgent
: ---
: 3.4.0
Assigned To: Yair Zaslavsky
Ondra Machacek
infra
:
Depends On:
Blocks: 1088123
  Show dependency treegraph
 
Reported: 2014-04-08 16:26 EDT by Michael Everette
Modified: 2016-02-10 14:20 EST (History)
15 users (show)

See Also:
Fixed In Version: org.ovirt.engine-root-3.4.0-14
Doc Type: Bug Fix
Doc Text:
Previously, if a user entered an incorrect password on the User Portal, the RHEV-M server sent the bad authentication to the Active Directory server repeatedly. This caused the account to be locked. After fixing this issue, an incorrect password is only sent once.
Story Points: ---
Clone Of:
: 1088123 (view as bug list)
Environment:
Last Closed: 2014-06-09 11:06:03 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: Infra
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
omachace: needinfo? (yzaslavs)


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 786253 None None None Never
oVirt gerrit 26664 None None None Never
oVirt gerrit 26696 ovirt-engine-3.4 MERGED core: Engine is sending bad credentials repeatdely Never
Red Hat Product Errata RHSA-2014:0506 normal SHIPPED_LIVE Moderate: Red Hat Enterprise Virtualization Manager 3.4.0 update 2014-06-09 14:55:38 EDT

  None (edit)
Description Michael Everette 2014-04-08 16:26:03 EDT
Description of problem:

After upgrading from 3.2 to 3.3.1 if a user enters an incorrect password on the User Portal, the RHEV-M server appears to send the bad authentication to the AD server repeatedly, locking the account.

Version-Release number of selected component (if applicable):

rhevm-3.3.1-0.48.el6ev.noarch

How reproducible:



Steps to Reproduce:
1. provide incorrect password when attempting to authenticate


Actual results:

user is locked out due to multiple attempts:

CanDoAction of action LoginUser failed. Reasons:USER_FAILED_TO_AUTHENTICATE_ACCOUNT_IS_LOCKED_OR_DISABLED


Expected results:

should fail once and allow for new attempt:

CanDoAction of action LoginUser failed. Reasons:USER_FAILED_TO_AUTHENTICATE
Comment 3 Yair Zaslavsky 2014-04-10 06:04:33 EDT
It can be seen that there is an attempt to query multiple ldap servers.

Can you provide us dig SRV _ldap._tcp.<DOMAIN> 

and dig SRV _kerberos._tcp.<DOMAIN>

where <DOMAIN> is the DNS domain?

I would like to verify that.


Many thanks!
Comment 16 Ondra Machacek 2014-04-30 06:58:48 EDT
Shouldn't be tried next ldap server for invalid username? Currently it's not.

Authentication Failed. Client not found in kerberos database.
2014-04-30 12:11:19,019 ERROR [org.ovirt.engine.core.bll.adbroker.DirectorySearcher] (ajp-/127.0.0.1:8702-4) Failed ldap search server LDAP://dc-02.ad2.rhev.lab.eng.brq.redhat.com:389 using user aaa@AD2.RHEV.LAB.ENG.BRQ.REDHAT.COM due to Authentication Failed. Client not found in kerberos database.. We should not try the next server

For bad password it just try one server and stop. Thus moving to verified.
Comment 17 errata-xmlrpc 2014-06-09 11:06:03 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2014-0506.html

Note You need to log in before you can comment on or make changes to this bug.