Red Hat Bugzilla – 1333381 – Updating password (after an administrative reset) for a certain user results in the password not being updated at all when password length has not enough characters
Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Updating password (after an administrative reset) for a certain user results in the password not being updated at all when password length has not enough characters
Description of problem:
Whenever a Sysadmin resets a password for a certain user and the user itself then tries to login with the temporary password filing out all the fields on the form the page is refreshed and fields such as the 'New password' and 'Verify Password' are cleared out without any single error notification. The password is however not updated and the login does not succeed.
Version-Release number of selected component (if applicable):
ipa-server-4.2.0-15.el7_2.6.1.x86_64
How reproducible:
Always
Steps to Reproduce:
1. Administratively reset a password for a certain user
2. Login with the temporary password
3. Fill out all the fields making sure the new password has a length of i.e 9 chars, then click on 'Reset Password and Login'
Actual results:
Login does not succeed and password is not updated. No errors appear.
Expected results:
Password updated and successful login.
Additional info:
The problems seems to appear whenever you use a password which has not enough chars. Additionally no errors do appear stating the new password is too short (where does FreeIPA defines the password requirements for a certain instance?), thus users are confused about why the password reset did not work as expected.
Thanks for reporting the bug. The issue will be handled in bug 1293870 or resp. bug 1309362
*** This bug has been marked as a duplicate of bug 1293870 ***