• Access denied for 1 user

  • Problems with installing OpenKM? No problemo, the solution is closer than you think.
Problems with installing OpenKM? No problemo, the solution is closer than you think.
Forum rules: Please, before asking something see the documentation wiki or use the search feature of the forum. And remember we don't have a crystal ball or mental readers, so if you post about an issue tell us which OpenKM are you using and also the browser and operating system version. For more info read How to Report Bugs Effectively.
 #25493  by S3SysAdmin
 
Hello everybody

We use OpenKM (Version: 5.1.10-SNAPSHOT build: 7560) with LDAP authentication running on Debian 2.6.32
We have about 700 users working on OpenKM since 2008
699 users have no problems (even new users) and they can access the application without problems.

but just old 1 user (with no problems in the past), now, cannot access because he gets:

"HTTP Status 403 - Access to the requested resource has been denied" from "JBossWeb/2.0.1.GA"

user's LDAP information are perfect (checked several times and never changed in the past)
We try different browser and different PC.. same result.

This is for sure an openKM issue...

I'm going crazy. Any idea??
 #25501  by S3SysAdmin
 
OK, I solved.

The problem was the user's password, which contains double $...
Changing the password, the problem disappears.

Thank you
 #25517  by jllort
 
Extrange problem. Normally problems comes with userid not with password. Two $ in password has generated it ? seems some kind of internal bug in jboss - ldap authentication
 #25518  by S3SysAdmin
 
Yes very very strange...

Originally, the user's password was Ale$$andro9
I changed the password to Abc01abc
I made the first login with success..
Later I re-changed the user's password to Ale$$andro9
and then the user was able to login with Ale$$andro9

Actually I'm a little bit confuse..
I didn't think the password value could make this kind of issues..
Maybe I'm wrong.. but for sure changing the passoword has solved the problem

Bye
 #25524  by pavila
 
Anyway I recommend to upgrade to OpenKM 6.2 because 5.1 branch is deprecated.
 #25530  by jllort
 
could be locked user by do not change password ? policy disable after sometime if you do not change password.
 #25538  by S3SysAdmin
 
the locked user condition or expired password was immediately excluded because
the user was able to login to all other systems without problems (all our systems use the same LDAP Server for authentication)

but it's simple to replicate the issue:

- create a test user on M$ active directory (call him testuser)
- set Ale$$andro9 as password (and uncheck "change on first login".. if you like set "passoword never expires")
- open web site and try to login with testuser /Ale$$andro9

does it work??

if it works... mahh.. maybe it's just my problem..
if it doesn't, change the password to Abc01abc and try again with testuser / Abc01abc
Now it should work.... re-change testuser's password again to Ale$$andro9 and try to login
it still should work..

About Us

OpenKM is part of the management software. A management software is a program that facilitates the accomplishment of administrative tasks. OpenKM is a document management system that allows you to manage business content and workflow in a more efficient way. Document managers guarantee data protection by establishing information security for business content.