You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@archiva.apache.org by ghostwolf59 <ma...@commerce.wa.gov.au> on 2014/09/17 07:19:15 UTC

Admin account issues migrating from v1.3.9 to 2.1.0

I have just upgraded from 1.3.9 to 2.1.0 
I have followed the upgrade path to the letter where I kept the users
directory and content. After a restart 2.1.0 fail to recognize my admin
account 
- when I request a password reset I receive the email, click the link and
provide a new password. 
The new password seem the be accepted even though no confirmation (message)
is sent. 
I am sent back to the default browse page though (still not logged on)
- Now when I try to login as admin using my updated password login fail.

Again I request a password reset - following the above with the same
outcome.

The logs does not indicate any issues with the reset - however, I have
noticed that my old and new admin password were sent to the archiva logs
(which to me seem to suggest a security flaw) 

The only way I manage to get this to work was to delete the users directory
which triggers a brand new admin account setup. 
Flow on problem with this is that all existing user accounts was blown away.

I raised a similar issue when I made an attempt to migrate from 1.3.6 to
2.0.1 a while back - so far no one have replied of offered some kind of
explanation.

According the the migration process there should be no issues keeping the
old user accounts.

I don't look forward re-creating every single account if/when we decide to
push this out to prod.

Earlier upgrades (1.3.x) have worked without any issues. 

Anyone experiencing similar issues or perhaps someone could enlighten me on
why this is happening.

cheers



--
View this message in context: http://archiva.996284.n3.nabble.com/Admin-account-issues-migrating-from-v1-3-9-to-2-1-0-tp16019.html
Sent from the Issues mailing list archive at Nabble.com.