PQ63243: SECJ0055A: AUTHENTICATION FAILED FOR WRONGUSER ON WEBSPHERE APPLICATION SERVER 4.03 WINDOWS 2000

APAR status
Closed as program error.

Error description
Authorization fails when using a Custom Registry if the
implementations of getUniqueUserId() and getUserSecurityName()
do not return the same string.
Local fix Problem summary
****************************************************************
* USERS AFFECTED: WebSphere Application Server users who have  *
*                 implemented a custom registry.               *
****************************************************************
* PROBLEM DESCRIPTION: Authorization from ltpa token may fail  *
*                      if user security name is different      *
*                      from user ID in custom registry.        *
****************************************************************
* RECOMMENDATION:                                              *
****************************************************************
Custom registry allow that a User ID is different the user's
security name, and user ID and user name got mixed.
Problem conclusion
Custom registry allow that a User ID is different the user's
security name, and access ID during authorization should be
based on user ID.
Temporary fix
A test fix was supplied and verified.
Comments
APAR information
APAR number PQ63243
Reported component name WEBSPHERE AE NT
Reported component ID 5630A2201
Reported release 400
Status CLOSED PER
PE NoPE
HIPER NoHIPER
Submitted date 2002-07-16
Closed date 2002-07-24
Last modified date 2003-04-30

APAR is sysrouted FROM one or more of the following:

APAR is sysrouted TO one or more of the following:

Modules/Macros
SECURITY          

Fix information
Fixed component name WEBSPHERE AE NT
Fixed component ID 5630A2201

Applicable component levels
R400 PSY    UP


Document Information


Product categories: Software > Application Servers > Distributed Application & Web Servers > WebSphere Application Server > General
Operating system(s):
Software version: 400
Software edition:
Reference #: PQ63243
IBM Group: Software Group
Modified date: Apr 30, 2003