Project

General

Profile

Actions

Defect #3097

closed

When authentication is delegated to a system (e. g., MS AD), user should not be able to be authenticated with expired credentials

Added by Tomáš Doischer about 2 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Roman Kučera
Category:
Authentication / Authorization
Target version:
Start date:
03/30/2022
Due date:
% Done:

100%

Estimated time:
Affected versions:
Owner:

Description

A customer reported suspicious behavior. In their environment, users use MS AD credentials to authenticate to IdM. In one case, a user was able to successfully authenticate using expired credentials.

The customer uses MS AD connected via WinRM+AD connector in a remote connector server.

The goal is to validate that this happens and if so, implement a different behavior (offer a password change to the user or, at least, prevent them from authentication).

Actions

Also available in: Atom PDF