Coder Social home page Coder Social logo

znuny4otrs-passwordpolicy's Introduction


Translation status


Znuny

Znuny is a continuation of the ((OTRS)) Community Edition (version 6.0.30) which was declared end of life (EOL) at the end of December 2020.

The primary goal for this project is to provide a maintained and stable version of the well known ticket system and improve it with new features.

The second goal is to reestablish a connection to the community.

License

The project is distributed under the GNU General Public License (GPL v3) - see the accompanying COPYING file for general license information. If you need more details you can have a look here.

Documentation

You can find documentation here. The source code of Znuny is publicly available on GitHub.

You want to get in touch?

Software requirements

Operating system

  • Linux (Debian or Red Hat preferred)
  • Perl 5.16.0 or higher

Web server

  • Apache 2 + mod_perl2 or higher (recommended)
  • Web server with CGI support (CGI is not recommended)

Databases

  • MySQL 8.0 or higher
  • MariaDB 10.3 or higher
  • PostgreSQL 12.0 or higher
  • Oracle 19c or higher

Browsers

  • These browsers are NOT supported:
    • Internet Explorer before version 11
    • Firefox before version 31
    • Safari before version 6

Vendor

This project is mainly funded by Znuny GmbH, Berlin. If you need professional support or consulting, feel free to contact us.

Znuny Website

znuny4otrs-passwordpolicy's People

Contributors

dennykorsukewitz avatar hanneshal avatar jepf avatar martini avatar nevermin avatar niklasschmitt avatar rkaldung avatar rolfschmidt avatar thorsteneckel avatar

Stargazers

 avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

znuny4otrs-passwordpolicy's Issues

Infinite Redirect in OTRS 3.3.5

Description:

  • user tries to log in
  • IF Agentinfo AND request for PW change are/should be shown the requests results in an error "ERR_TOO_MANY_REDIRECTS"

Reported by customer using:

ITSM
CustomerCompanyImportExport (c.a.p.e. IT Vers. 1.4.0)
CustomerUserImportExport (c.a.p.e. IT Vers. 1.10.0)
DynamicFieldITSMConfigItem (c.a.p.e. IT Vers. 1.1.0)
FAQ (OTRS)
GeneralCatalog (OTRS)
ImportExport (OTRS)
iPhoneHandle (OTRS)
ITSM-CIAttributeCollection (c.a.p.e. IT Vers. 2.3.0)
OTRSMAsterSlave (OTRS)
Support, Survey und TimeAccounting (OTRS)

System OTRS 3.3.5.

OTRS Log shows:

Wed Apr 30 13:39:43 2014    notice  OTRS-CGI-12     User: USERNAME authentication ok
(Method: sha256, REMOTE_ADDR: xxx.xxx.xxx.xxx).

repeated 8 times in 2 seconds.

Password Policy with Two Factor Authentication (2FA)

Hi
On OTRS 6.0.30 have enabled the package Znuny4OTRS-PasswordPolicy 6.0.6, all work fine till enabled two-factor authentication (2FA) so the agents cannot change his/her password.

With both option enabled (Znuny4OTRS-PasswordPolicy and 2FA) when the Agent must change the password the system does not accept the new password because (i think) expects the token, to validate the change.

How to reproduce

After installed and configure Password Policy (these are mine settings)
image

Go to System Configuration > Core > Auth > Agent > TwoFactor
Enable only AuthTwoFactorModule and leave the others settings by default
image

When Agent have to change the password the screen are like this
image

image

from system log i see this entries
image

Server

  • OS: OpenSUSE
  • OTRS version 6.0.30

Client

  • Browser: any
  • Windows 10

Additional information

As mention before, if disable 2FA the add-on PasswordPolicy work well
NOTE: i changed PasswordMaxValidTimeInDays to 60 (that are differ from change password screen) to temporary permit Agent login without disable 2FA

Thanks in advance
naitso

Bug - Customer User won't be locked after multiple failed logins

Expected behavior

Set setting PasswordMaxLoginFailed affectes CustomerUser login.

Actual behavior

Despite the setting PasswordMaxLoginFailed and way more login attempts the CustomerUser does not become invalid-temporary like agents.

How to reproduce

Steps to reproduce the behavior:

  1. Configure a value PasswordMaxLoginFailed
  2. Login in multiple times (>PasswordMaxLoginFailed) as a CustomerUser with a wrong password.
  3. Check that the CustomerUser is still valid.

Environment

  • OS: n.a.
  • Browser: n.a.
  • OTRS version 6.0.35

Additional information

PasswordMaxLoginFailed is a setting form the Framework and not found in any file related to CustomerUser. It's expected to work with datasources not read-only and type DB (or wherever the valid flag can be changed)

Service User

Hi, I plan to use some customer as "service user" to permit the creation of new tickets through WSDL for an automatic task.
Is possible to inhibit the password policy for a specific group of customers? Or, are there other method to use for create a "service user" that should not expire ?
Thanks in advance
Cristian

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.