Bug 49336 - Expired password should be handled better
Expired password should be handled better
Status: RESOLVED DUPLICATE of bug 50594
Product: UCS
Classification: Unclassified
Component: SAML
UCS 4.4
Other All
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
: 46028 (view as bug list)
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-04-23 12:51 CEST by Michael Grandjean
Modified: 2019-12-04 20:19 CET (History)
3 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 5: Major Usability: Impairs usability in key scenarios
Who will be affected by this bug?: 3: Will affect average number of installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.171
Enterprise Customer affected?:
School Customer affected?: Yes
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Grandjean univentionstaff 2019-04-23 12:51:51 CEST
Scenario:

I use an external service like, Office 365. I browse to office.com and want to login. I am redirected to the UCS SAML login and enter my credentials. I do have a valid user account, but my password is expired. The SAML login then tells me, that "An LDAP password change is required before login is possible". Most end users are stuck here, because there is no hint where or how to change the password.

Imho we should offer a link to the UMC password change, but the URL most be configurable. Automatically linking to the FQDN of the UCS master won't be enough, because more and more SAML-Logins/Portals/UMCs are made accessible from the internet via a different URL. Also, the customer could link to the Self Service App this way, if installed.
Comment 1 Erik Damrose univentionstaff 2019-04-23 12:56:19 CEST
*** Bug 46028 has been marked as a duplicate of this bug. ***
Comment 2 Ingo Steuwer univentionstaff 2019-12-04 20:19:31 CET
the proposal in #50594 has the same approach with a few more details, so I close this one as duplicate

*** This bug has been marked as a duplicate of bug 50594 ***