Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-27407

Default text password imported through LDAP allows users to sign in with any password

    Details

      Description

      Replicated: 6.1.10, 6.1.x (Rev. 110292), Trunk (Rev. 110292)

      portal-ext.properties:
      ldap.import.user.password.enabled=false
      ldap.import.user.password.autogenerated=false
      ldap.import.user.password.default=test

      1. Sign in as test@liferay.com
      2. Set up LDAP server with import enabled
      3. Make sure the LDAP password of imported users, test2@liferay.com and test3@liferay.com, is set as "root"
      4. Sign into test2@liferay.com using any word even the default password "test", make sure it's not the LDAP password "root"
      5. LDAP Authentication error stack trace will show up in the logs, but the user will still be logged in.
      6. User will also be prompted to reset their password, but "test" is set as the imported password. "Your new password cannot be the same as your old password. Please enter in a different password."
      6. Sign into test3@liferay.com using the LDAP password, "root"
      7. User would be prompted to reset their password with no stack trace, but "test" is still set as the imported password, "Your new password cannot be the same as your old password. Please enter in a different password."
      8. Even after signing in and the user has been imported with passwords reset, all passwords allow login. If signing in using the LDAP password, there is still no stack trace.

      NOTE:
      a. If import is not enabled, can only login using the LDAP password. After logging in, the imported password seems to be "test". Same message "Your new password cannot be the same as your old password. Please enter in a different password." when trying to reset password.
      b. Have also tried setting "ldap.import.user.password.default=password"

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Days since last comment:
                  7 years, 16 weeks, 5 days ago

                  Packages

                  Version Package
                  6.0.X EE
                  6.1.1 CE GA2
                  6.1.20 EE GA2
                  --Sprint 11/12
                  6.2.0 CE M2