Bug 31587 - Radius authentication ignores "Account deactivation"
Radius authentication ignores "Account deactivation"
Status: CLOSED FIXED
Product: UCS@school
Classification: Unclassified
Component: Radius
UCS@school 3.1
Other Linux
: P5 normal (vote)
: UCS@school 3.1 R2 Errata
Assigned To: Janek Walkenhorst
Felix Botner
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-05-30 16:32 CEST by Felix Botner
Modified: 2013-08-15 09:45 CEST (History)
2 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Felix Botner univentionstaff 2013-05-30 16:32:23 CEST
I have a user with

Account deactivation: All disabled
Locked login methods: Lock all login methods

but im still able to login to the radius server with that user.
Comment 1 Sönke Schwardt-Krummrich univentionstaff 2013-07-16 09:50:29 CEST
A sucessful authentication (e.g. login at the wireless accesspoint) should only be possible if the samba flags "locked" and "deactivated" are not set for that user. It has to be tested, if the S4 connector syncs these flags between AD and UCS LDAP.
Comment 2 Janek Walkenhorst univentionstaff 2013-07-18 13:29:59 CEST
(In reply to Sönke Schwardt-Krummrich from comment #1)
> It has to be tested, if the S4 connector syncs these flags
> between AD and UCS LDAP.
The "D" flag is synced correctly.
Comment 3 Janek Walkenhorst univentionstaff 2013-07-18 14:07:43 CEST
(In reply to Sönke Schwardt-Krummrich from comment #1)
> It has to be tested, if the S4 connector syncs these flags
> between AD and UCS LDAP.
The "L" flag is NOT synced.
Comment 4 Janek Walkenhorst univentionstaff 2013-07-18 14:36:12 CEST
(In reply to Janek Walkenhorst from comment #3)
> (In reply to Sönke Schwardt-Krummrich from comment #1)
> > It has to be tested, if the S4 connector syncs these flags
> > between AD and UCS LDAP.
> The "L" flag is NOT synced.Bug #32010
Comment 5 Janek Walkenhorst univentionstaff 2013-07-18 14:55:06 CEST
\item The WLAN 802.1x integration (\ucsName{ucs-school-radius-802.1x}) now disallows access when an account is locked or disabled (\ucsBug{31587}).

ucs-school-radius-802.1x (3.0.1-1) unstable; urgency=low

  * deny WLAN access for disabled/locked accounts (Bug #31587)
Comment 6 Felix Botner univentionstaff 2013-07-23 12:18:16 CEST
OK - ucs-school-radius-802.1x (account deactivation, locked login methods)
OK - changelog
Comment 7 Sönke Schwardt-Krummrich univentionstaff 2013-08-15 09:45:19 CEST
UCS@school 3.1 R2-1 has been released:
http://download.univention.de/doc/release-notes-ucsschool-3.1-rev2-1.pdf

If this error occurs again, please use "Clone This Bug".