Hi all.
We have a single server hosting Crowd, Stash, FishEye, Bamboo and JIRA anc Crowd is providing active directory authentication for the other four products.
Since changing my domain password, I've found that my JIRA failed login count has gone through the roof. The security log even shows failed logins for times that I've not been in the office. Typically, I'll go to use JIRA and it'll prompt me for a CAPTCHA login, and I'll have to go through the following process before I can get in:
- Login with my real credentials and provide CAPTCHA (fails).
- Login in with bogus credentials and provide CAPTCHA (fails).
- Login in my real credentials, no CAPTCHA required (fails).
- Login with my real credentials and provide CAPTCHA (works).
This happens quite frequently, and it's only happening to two of us in the office since we changed our network passwords, and I can't work out why. I even tried setting the CAPTCHA failed login maximum to unlimited, but it still requests it.
Looking at the log files, I also found that when it does decide to randomly fail a login, it doesn't increase the login fail count by one, but by eight, as evidenced by these consecutive log entries:
anonymous /browse/(issue) The user '(Username)' is required to answer a CAPTCHA elevated security check. Failure count equals 13
anonymous /login.jsp The user '(Username)' is required to answer a CAPTCHA elevated security check. Failure count equals 14
anonymous /login.jsp The user '(Username)' is required to answer a CAPTCHA elevated security check. Failure count equals 15
anonymous /captcha The user '(Username)' is required to answer a CAPTCHA elevated security check. Failure count equals 16
anonymous /rest/helptips/1.0/tips The user '(Username)' is required to answer a CAPTCHA elevated security check. Failure count equals 17
anonymous /rest/menu/latest/appswitcher The user '(Username)' is required to answer a CAPTCHA elevated security check. Failure count equals 18
anonymous /rest/nav-links-analytics-data/1.0/ The user '(Username)' is required to answer a CAPTCHA elevated security check. Failure count equals 19
anonymous /rest/api/2/attachment/meta The user '(Username)' is required to answer a CAPTCHA elevated security check. Failure count equals 20
This means that my failed login count can reach the thousands, which is crazy.
I tried uninstalling the Atlassian connector from Visual Studio, in the hopes that this was causing the failed logins, but it's still happening. I'm very close to adding a trigger to the right table so that as soon as the failed login count goes up by one, it's immediately set back to zero! But I imagine I'd still be logged out - it's just that I wouldn't be faced with a CAPTCHA request each time.
Any ideas?