SoftTree Technologies SoftTree Technologies
Technical Support Forums
RegisterSearchFAQMemberlistUsergroupsLog in
Authentication in windows version 24x7

 
Reply to topic    SoftTree Technologies Forum Index » 24x7 Scheduler, Event Server, Automation Suite View previous topic
View next topic
Authentication in windows version 24x7
Author Message
LeeD



Joined: 17 May 2007
Posts: 311
Country: New Zealand

Post Authentication in windows version 24x7 Reply with quote
So....I have an account defined in 24x7 win version with the same name as my domain account and a password that is different.

When I accidentally entered my domain password to log into that 24x7 account this morning it let me in....so what does the integrated security do if anything if it's not authing the password?
Sun Mar 14, 2010 4:36 pm View user's profile Send private message
SysOp
Site Admin


Joined: 26 Nov 2006
Posts: 6500

Post Reply with quote
Can you confirm that "enable user-level security in this job database" option is checked in the scheduler settings?
Sun Mar 14, 2010 9:08 pm View user's profile Send private message
LeeD



Joined: 17 May 2007
Posts: 311
Country: New Zealand

Post Reply with quote
It sure is
Sun Mar 14, 2010 9:30 pm View user's profile Send private message
SysOp
Site Admin


Joined: 26 Nov 2006
Posts: 6500

Post Reply with quote
In version 3.x it is supposed to be using your password in the scheduler settings. In v4.x it is supposed to be using your network credentials.


Just one little thing, you are not trying it with Test Connect, are you? Test Connect is a sort of "ping" for pinging physical connections. It prompts for user id/password because it needs it for a physical connection, but it doesn't authenticate your user at that stage. If you do a normal connect, then it is going to authenticate your connection.
Sun Mar 14, 2010 10:41 pm View user's profile Send private message
LeeD



Joined: 17 May 2007
Posts: 311
Country: New Zealand

Post Reply with quote
No not test connect it's a full connection, shows job tree and I can browse freely. This is through 24x7 remote control console.
Sun Mar 14, 2010 11:42 pm View user's profile Send private message
SysOp
Site Admin


Joined: 26 Nov 2006
Posts: 6500

Post Reply with quote
We couldn't find a way to reproduce this issue. Are you able to reproduce it on demand?
Mon Mar 15, 2010 3:42 pm View user's profile Send private message
LeeD



Joined: 17 May 2007
Posts: 311
Country: New Zealand

Post Reply with quote
Yep, I just did it. To restate, I have an admin level account within a 24x7 running as a service with user level security on and a password defined which is different from my domain account, which has the same username and is an admin on that box.

I start up 24x7 remote control from my laptop(logged into windows with my domain account), point it at the server, it asks me to log in, I can enter my domain password to authenticate and I get full access to the job db. I can also enter the password on the 24x7 account. Even worse, I've just tried a string of nonsense and even that will let me in. I don't even need to enter a username which is valid.

I will try with another account logged into my workstation to see whether this is just making a leap to domain auth or if it's actually really insecure.
Mon Mar 15, 2010 5:40 pm View user's profile Send private message
SysOp
Site Admin


Joined: 26 Nov 2006
Posts: 6500

Post Reply with quote
That likely indicates that the security option is not enabled in the settings and you can login using any name and password. I suggest stopping the service, starting 24x7 in GUI mode and verifying the security option state.
Mon Mar 15, 2010 5:55 pm View user's profile Send private message
LeeD



Joined: 17 May 2007
Posts: 311
Country: New Zealand

Post Reply with quote
Considering that I need to log in properly to the web console thats not the case. Only the correct 24x7 valid uname and password will let me in there.
Wed Mar 17, 2010 12:21 am View user's profile Send private message
SysOp
Site Admin


Joined: 26 Nov 2006
Posts: 6500

Post Reply with quote
Which version of 24x7 are you running on your laptop? server?
Wed Mar 17, 2010 12:40 am View user's profile Send private message
SysOp
Site Admin


Joined: 26 Nov 2006
Posts: 6500

Post Reply with quote
I was able to reproduce that in 3.6.5 There is surely some defect, perhaps a side effect of some other change. This issue status has been elevated to top level.
Wed Mar 17, 2010 3:26 pm View user's profile Send private message
LeeD



Joined: 17 May 2007
Posts: 311
Country: New Zealand

Post Reply with quote
The remote control client is 3.6.6 while the server is 3.6.1
Wed Mar 17, 2010 5:59 pm View user's profile Send private message
SysOp
Site Admin


Joined: 26 Nov 2006
Posts: 6500

Post Reply with quote
Hi,

Version 3.6.9 has been released. This version fixes the security flow in the 24x7 Remote Console. For best results you should upgrade both the server and the client computers.

The download link is available on the product home page http://www.softtree.com/24x7/index.shtml
Fri Mar 26, 2010 12:24 am View user's profile Send private message
Display posts from previous:    
Reply to topic    SoftTree Technologies Forum Index » 24x7 Scheduler, Event Server, Automation Suite All times are GMT - 4 Hours
Page 1 of 1

 
Jump to: 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


 

 

Powered by phpBB © 2001, 2005 phpBB Group
Design by Freestyle XL / Flowers Online.