Red Hat Bugzilla – Bug 718062
When admin resets a user's password with "ipa passwd" user's failed log in count is not reset
Last modified: 2015-01-04 18:49:48 EST
Description of problem: Once a user has reached max failed login attempts, an admin should be able to reset the password with ipa passwd and this should reset the failed login counter back to 0. It is not resetting the counter Version-Release number of selected component (if applicable): ipa-server-2.0.99-2.20110629T0200zgit66eeace.el6.x86_64 How reproducible: Steps to Reproduce: 1. add a new user and set the user's password 2. kinit as the user and change the password 3. kinit as the user with an invalid password 4. kinit as admin and check the user's failure count. # ipa user-show --all <userid> should see "krbloginfailedcount: 1" 5. reset the user's password as an admin # ipa passwd <userid> 6. check the user's failure count. # ipa user-show --all <userid> should see "krbloginfailedcount: 0" Actual results: Counter is not reset when password is reset by an admin Expected results: Counter to be reset to 0, when password is reset by an admin Additional info:
https://fedorahosted.org/freeipa/ticket/1441
Fixed upstream: master: https://fedorahosted.org/freeipa/changeset/f534445e26ebfca38afe1c834ba088cbcbc24e37 ipa-2-0: https://fedorahosted.org/freeipa/changeset/5cd7a92c9c7a6a1d9ef67515b7a280832cb6c651
Verified: :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ LOG ] :: Verify Failure Counter Reset with Admin Password Reset :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ LOG ] :: ERROR: kinit as user1 with password BADPWD failed. :: [ PASS ] :: Kinit as user with invalid password :: [ LOG ] :: kinit as admin with password Secret123 was successful. :: [ PASS ] :: Running 'kinitAs admin Secret123' :: [ PASS ] :: User's failed counter is as expected: [1] :: [ LOG ] :: kinit as admin with password Secret123 was successful. :: [ PASS ] :: Running 'kinitAs admin Secret123' :: [ PASS ] :: Verify Password Change was successful. :: [ PASS ] :: User's failed counter is as expected: [0] :: [ LOG ] :: Duration: 16s :: [ LOG ] :: Assertions: 6 good, 0 bad :: [ PASS ] :: RESULT: Verify Failure Counter Reset with Admin Password Reset version: ipa-server.x86_64 0:2.0.99-3.20110713T1714zgit02520ab.el6 Waiting for all acks and for bug to be in modified state before marking bug verified.
Technical note added. If any revisions are required, please edit the "Technical Notes" field accordingly. All revisions will be proofread by the Engineering Content Services team. New Contents: Do not document
Marking as VERIFIED as per comment #4.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2011-1533.html