Hi guys,
I've been knocking my head against the wall a couple days on this one. I exported a jira on-demand instance, and imported it into a standalone fresh-install of jira 6.2.1 -- I made sure to do the restore option from the wizard. The installation works fine, the index works fine -- however, I can't log in.
I have followed these wikis:
https://confluence.atlassian.com/display/JIRA/Retrieving+the+JIRA+Administrator
https://confluence.atlassian.com/display/JIRA/Migrating+from+JIRA+OnDemand+to+a+JIRA+Installed+Site
Right after migration,
sysadmin/sysadmin credentials don't work.
Resetting password to encrypted "sphere" in mysql db, and restarting jira doesn't work. Let me show what I see in the DB after I fail to log into newly migrated instance as sysadmin/sysadmin, right after I change password to "spehere"--:
mysql> select * from schemepermissions where PERMISSION=0;
+-------+--------+------------+-----------+----------------+
| ID | SCHEME | PERMISSION | perm_type | perm_parameter |
+-------+--------+------------+-----------+----------------+
| 10000 | NULL | 0 | group | administrators |
| 13702 | NULL | 0 | group | administrators |
| 13703 | NULL | 0 | group | administrators |
| 16900 | NULL | 0 | group | site-admins |
+-------+--------+------------+-----------+----------------+
4 rows in set (0.00 sec)
mysql> select * from schemepermissions where PERMISSION=1;
+-------+--------+------------+-----------+----------------+
| ID | SCHEME | PERMISSION | perm_type | perm_parameter |
+-------+--------+------------+-----------+----------------+
| 16901 | NULL | 1 | group | jira-users |
+-------+--------+------------+-----------+----------------+
1 row in set (0.01 sec)
mysql> select * from schemepermissions where PERMISSION=44;
+-------+--------+------------+-----------+---------------------------+
| ID | SCHEME | PERMISSION | perm_type | perm_parameter |
+-------+--------+------------+-----------+---------------------------+
| 13704 | NULL | 44 | group | system-administrators |
| 13705 | NULL | 44 | group | confluence-administrators |
+-------+--------+------------+-----------+---------------------------+
2 rows in set (0.00 sec)
mysql> select child_name, directory_id from cwd_membership where parent_name='system-administrators';
+------------+--------------+
| child_name | directory_id |
+------------+--------------+
| sysadmin | 1 |
+------------+--------------+
1 row in set (0.00 sec)
From the above information, it seems that sysadmin has the global permissions necessary to log in.
Here is record of sysadmin, showing sphere password:
mysql> select * from cwd_user where user_name = "sysadmin";
+-------+--------------+-----------+-----------------+--------+---------------------+---------------------+------------+------------------+---------------+-----------------+----------------------+----------------------+--------------------+---------------------+------------------------------------------------------------------------------------------+--------------------+-------------+
| ID | directory_id | user_name | lower_user_name | active | created_date | updated_date | first_name | lower_first_name | last_name | lower_last_name | display_name | lower_display_name | email_address | lower_email_address | CREDENTIAL | deleted_externally | EXTERNAL_ID |
+-------+--------------+-----------+-----------------+--------+---------------------+---------------------+------------+------------------+---------------+-----------------+----------------------+----------------------+--------------------+---------------------+------------------------------------------------------------------------------------------+--------------------+-------------+
| 12354 | 1 | sysadmin | sysadmin | 1 | 2012-07-25 09:09:11 | 2013-09-30 23:29:56 | System | system | Administrator | administrator | System Administrator | system administrator | sysadmin@localhost | sysadmin@localhost | uQieO/1CGMUIXXftw3ynrsaYLShI+GTcPS4LdUGWbIusFvHPfUzD7CZvms6yMMvA8I7FViHVEqr6Mj4pCLKAFQ== | NULL | 32769:65537 |
+-------+--------------+-----------+-----------------+--------+---------------------+---------------------+------------+------------------+---------------+-----------------+----------------------+----------------------+--------------------+---------------------+------------------------------------------------------------------------------------------+--------------------+-------------+
As you can see, user is active.
Here is a list of the directories:
mysql> select * from cwd_directory;
+----+-------------------------+-------------------------+---------------------+---------------------+--------+---------------------------------+-------------------------------------------------+-------------------------------------------------+----------------+--------------------+
| ID | directory_name | lower_directory_name | created_date | updated_date | active | description | impl_class | lower_impl_class | directory_type | directory_position |
+----+-------------------------+-------------------------+---------------------+---------------------+--------+---------------------------------+-------------------------------------------------+-------------------------------------------------+----------------+--------------------+
| 1 | JIRA Internal Directory | jira internal directory | 2012-07-25 09:09:07 | 2012-07-25 09:27:30 | 1 | JIRA default internal directory | com.atlassian.crowd.directory.InternalDirectory | com.atlassian.crowd.directory.internaldirectory | INTERNAL | 0 |
+----+-------------------------+-------------------------+---------------------+---------------------+--------+---------------------------------+-------------------------------------------------+-------------------------------------------------+----------------+--------------------+
1 row in set (0.00 sec)
-- clearly, I don't have the jira-administrators or jira-system-administrators groups created in this example. In past attempts, I have followed all wiki steps, creating these groups, and also assign them to sysadmin. I had also tried creating a separate localadmin user with these groups.
Despite all my attempts, I continue to get errors like this when I try to log in:
2014-03-20 17:01:16,684 http-bio-8080-exec-7 anonymous 1021x35x1 rhm6wd 10.26.102.188 /rest/gadget/1.0/login runAuthentication : 'sysadmin' does not require elevated security check. Attempting authentication...
2014-03-20 17:01:16,780 http-bio-8080-exec-7 anonymous 1021x35x1 rhm6wd 10.26.102.188 /rest/gadget/1.0/login login : 'sysadmin' has been authenticated
2014-03-20 17:01:16,784 http-bio-8080-exec-7 anonymous 1021x35x1 rhm6wd 10.26.102.188 /rest/gadget/1.0/login The user 'sysadmin' is NOT AUTHORIZED to perform to login for this request
2014-03-20 17:01:16,784 http-bio-8080-exec-7 anonymous 1021x35x1 rhm6wd 10.26.102.188 /rest/gadget/1.0/login authoriseUser : 'sysadmin' CANNOT login according to the RoleMapper
2014-03-20 17:01:16,784 http-bio-8080-exec-7 anonymous 1021x35x1 rhm6wd 10.26.102.188 /rest/gadget/1.0/login login : 'sysadmin' tried to login but they do not have USE permission or weren't found. Deleting remember me cookie.
2014-03-20 17:01:16,784 http-bio-8080-exec-7 anonymous 1021x35x1 rhm6wd 10.26.102.188 /rest/gadget/1.0/login runAuthentication : 'sysadmin' was UNSUCCESSFULLY authenticated
-- it appears that user authenticates, but then can't proceed due to Role mapper issues? I feel like I am missing something. Some check or configuration that I am overlooking?