Support #11502

[SCP ID :##5727##] : Error 'Invalid Username or Password' during login

Added by Zahir Abd Latif over 3 years ago. Updated over 3 years ago.

Status:Closed - End of life cycleStart date:January 21, 2021
Priority:ImmediateDue date:
Assignee:Nurul Athira Abdul Rahim% Done:

100%

Category:-Spent time:-
Target version:-

Description

Hi,
Kindly attend below request:-

Error 'Invalid Username or Password' prompt in CDB login page even user insert correct username/password.

History

#1 Updated by Nurul Athira Abdul Rahim over 3 years ago

  • Status changed from New - Begin Life Cycle to Pending Review
  • % Done changed from 0 to 100

*Update script on production (220121)

Root Cause

1. IBAM Password Policy for Password Expiry Days is set to 150
2. Users will get a message when their password is 149 days old because there is a notification alert 1 days before
3. However, the error message is 'Invalid username or password' instead of 'Password will expire tomorrow'
4. Also, there was a user migration in August 2020 and their password is expiring in January 2021

Solution :

1. Disable notification alert and shows 'Password expired. Please request new password by clicking Forgot Password' on the expiry date
2. Please take note Pentest requested to change all Login error message to ' Invalid username or password '

Script : update dbo.TB_AM_CONFIG set CONFIG_VALUE='0' where CONFIG_NAME='NOTIF_ALERT' or CONFIG_NAME='CONFIG_CHANGE';

#2 Updated by Nurul Athira Abdul Rahim over 3 years ago

  • Status changed from Pending Review to Closed - End of life cycle

Migration ID ID0028

Also available in: Atom PDF