Login via email is not working anymore (invalid_credentials)
Summary
Fore some time I'm not able to login via mail. Only the login with my user account is working.
Steps to reproduce
Go to my instance of gitlab-ee and try to login. With my username its working but when I try my E-Mail Address and my password it shows: "Could not authenticate you from Ldapmain because "Invalid credentials". (Maybe this occurred, because we played around with kerberos Single Sing On?) But we stopped our tests and set gitlab_rails['kerberos_enabled'] = false
Expected behavior
Because I set the value allow_username_or_email_login: true for ldap_servers the config file I would expect that the login should work with both: email and username. I think this was working some time ago. The e-mail is read correctly from ldap for my account. When I open my user account in gitlab it shows the right address under "Email"
Actual behavior
- Login with username and password -> login successful
- Login with e-mail and password -> login unsuccessful
- Login with username@domain and password -> login successful
Relevant logs and/or screenshots
production.log
Processing by OmniauthCallbacksController#failure as HTML
Parameters: {"utf8"=>"✓", "authenticity_token"=>"***=", "username"=>"jan.sippli@dlr.de", "password"=>"[FILTERED]"}
Redirected to https://mygitlab.de/users/sign_in
Completed 302 Found in 36ms (ActiveRecord: 2.8ms)
Started GET "/users/sign_in" for ***.***.***.*** at 2016-11-01 07:52:17 +0100
Processing by SessionsController#new as HTML
Completed 200 OK in 158ms (Views: 111.3ms | ActiveRecord: 5.3ms)
Processing by OmniauthCallbacksController#ldapmain as HTML
Parameters: {"utf8"=>"✓", "authenticity_token"=>"***", "username"=>"sipp_ja", "password"=>"[FILTERED]"}
Redirected to https://mygitlab.de/
Completed 302 Found in 345ms (ActiveRecord: 23.8ms)
Started GET "/" for ***.***.***.*** at 2016-11-01 07:52:23 +0100
Processing by RootController#index as HTML
unicorn_stdout.log
E, [2016-11-01T07:52:17.439523 #12018] ERROR -- omniauth: (ldapmain) Authentication failure! invalid_credentials encountered.
I, [2016-11-01T07:52:22.390651 #12027] INFO -- omniauth: (ldapmain) Callback phase initiated.
curl --request GET --header "PRIVATE-TOKEN: *" 'https:///api/v3/users?username=sipp_ja'
[{"name":"Sippli, Jan","username":"sipp_ja","id":2,"state":"active","avatar_url":null,"web_url":"https://**********/sipp_ja","created_at":"2016-04-28T11:53:30.334+02:00","is_admin":true,"bio":"","location":"","skype":"","linkedin":"","twitter":"","website_url":"","organization":null,"last_sign_in_at":"2016-11-01T07:37:02.154+01:00","confirmed_at":"2016-04-28T11:53:30.246+02:00","email":"jan.sippli@dlr.de","theme_id":2,"color_scheme_id":1,"projects_limit":25,"current_sign_in_at":"2016-11-01T07:52:23.058+01:00","identities":[{"provider":"kerberos","extern_uid":"sipp_ja@*********"},{"provider":"ldapmain","extern_uid":"CN=sipp_ja,OU=Benutzer,OU=_Global,OU=****,OU=******,OU=*****,DC=****,DC=****,DC=****"}],"can_create_group":true,"can_create_project":true,"two_factor_enabled":false,"external":false}]
Output of checks
Results of GitLab application Check
Checking GitLab Shell ...
GitLab Shell version >= 3.6.6 ? ... OK (3.6.6)
Repo base directory exists?
default... yes
Repo storage directories are symlinks?
default... no
Repo paths owned by git:git?
default... yes
Repo paths access is drwxrws---?
default... yes
hooks directories in repos are links: ...
21/3 ... ok
21/10 ... ok
21/21 ... ok
21/23 ... ok
21/24 ... ok
21/25 ... ok
44/35 ... ok
44/36 ... ok
44/37 ... ok
21/51 ... ok
44/52 ... ok
44/53 ... ok
51/56 ... ok
43/57 ... ok
20/58 ... ok
20/59 ... ok
46/65 ... ok
44/66 ... ok
20/67 ... ok
20/68 ... ok
20/69 ... ok
20/70 ... ok
20/71 ... ok
20/73 ... ok
51/74 ... ok
33/75 ... ok
33/76 ... ok
47/77 ... ok
33/78 ... repository is empty
33/79 ... ok
33/80 ... ok
33/81 ... ok
33/82 ... ok
33/83 ... ok
33/84 ... ok
33/85 ... ok
33/86 ... ok
33/87 ... ok
33/88 ... ok
33/89 ... repository is empty
33/90 ... ok
33/91 ... ok
33/92 ... ok
42/97 ... ok
24/115 ... ok
64/116 ... ok
120/117 ... ok
63/120 ... ok
120/122 ... ok
24/123 ... ok
32/125 ... ok
32/126 ... ok
32/127 ... ok
32/128 ... ok
32/129 ... ok
31/130 ... ok
74/131 ... ok
71/132 ... ok
71/133 ... ok
33/143 ... ok
74/144 ... ok
2/145 ... ok
2/146 ... ok
43/147 ... ok
83/153 ... ok
57/154 ... ok
57/155 ... ok
33/157 ... ok
83/159 ... ok
83/161 ... ok
83/163 ... ok
83/164 ... ok
74/166 ... ok
62/167 ... ok
33/168 ... ok
74/170 ... ok
74/171 ... ok
91/172 ... ok
44/173 ... ok
57/175 ... ok
57/176 ... ok
57/177 ... ok
57/178 ... ok
93/180 ... ok
93/181 ... ok
37/182 ... ok
66/183 ... ok
67/184 ... ok
67/185 ... ok
67/187 ... ok
33/188 ... ok
96/189 ... ok
33/190 ... ok
33/191 ... ok
33/192 ... ok
2/193 ... ok
37/194 ... ok
35/197 ... ok
51/198 ... ok
76/199 ... ok
6/201 ... ok
40/202 ... ok
40/203 ... ok
6/204 ... ok
66/205 ... ok
66/206 ... ok
43/207 ... ok
43/208 ... ok
82/210 ... ok
41/211 ... ok
43/212 ... ok
83/213 ... ok
52/214 ... ok
52/215 ... ok
81/216 ... ok
103/217 ... ok
103/218 ... ok
81/219 ... ok
94/220 ... ok
2/222 ... repository is empty
105/224 ... ok
105/225 ... ok
105/227 ... ok
105/229 ... ok
34/230 ... ok
34/231 ... ok
34/233 ... ok
34/234 ... ok
34/235 ... ok
50/237 ... ok
50/238 ... ok
50/239 ... ok
50/240 ... ok
50/242 ... ok
33/243 ... ok
33/245 ... ok
33/246 ... ok
110/247 ... ok
110/248 ... ok
43/250 ... ok
120/251 ... ok
112/252 ... ok
112/253 ... ok
112/254 ... ok
105/255 ... ok
105/259 ... ok
105/263 ... ok
105/264 ... ok
60/265 ... repository is empty
42/266 ... ok
42/267 ... ok
42/268 ... ok
42/269 ... ok
42/270 ... ok
42/271 ... ok
42/273 ... ok
42/274 ... ok
42/275 ... ok
42/276 ... ok
42/279 ... ok
42/280 ... ok
41/282 ... ok
41/283 ... ok
60/285 ... ok
60/286 ... ok
60/289 ... ok
60/290 ... ok
60/292 ... ok
60/293 ... ok
60/296 ... ok
60/297 ... ok
60/299 ... ok
60/300 ... ok
42/301 ... ok
43/302 ... ok
105/304 ... ok
41/305 ... ok
41/307 ... ok
62/308 ... ok
114/313 ... ok
79/314 ... ok
111/315 ... repository is empty
92/316 ... ok
33/317 ... ok
81/318 ... ok
79/319 ... ok
119/320 ... ok
79/321 ... ok
119/322 ... repository is empty
120/323 ... ok
35/324 ... ok
40/325 ... repository is empty
71/326 ... repository is empty
83/327 ... ok
4/328 ... ok
87/329 ... ok
6/330 ... ok
126/331 ... ok
63/332 ... ok
112/333 ... ok
82/334 ... repository is empty
Running /opt/gitlab/embedded/service/gitlab-shell/bin/check
Check GitLab API access: OK
Access to /var/opt/gitlab/.ssh/authorized_keys: OK
Send ping to redis server: OK
gitlab-shell self-check successful
Checking GitLab Shell ... Finished
Checking Sidekiq ...
Running? ... yes
Number of Sidekiq processes ... 1
Checking Sidekiq ... Finished
Checking Reply by email ...
IMAP server credentials are correct? ... yes
Init.d configured correctly? ... skipped (omnibus-gitlab has no init script)
MailRoom running? ... can't check because of previous errors
Checking Reply by email ... Finished
Checking LDAP ...
LDAP users with access to your GitLab server (only showing the first 100 results)
Server: ldapmain
[REMOVED]
Checking LDAP ... Finished
Checking GitLab ...
Git configured with autocrlf=input? ... yes
Database config exists? ... yes
All migrations up? ... yes
Database contains orphaned GroupMembers? ... no
GitLab config exists? ... yes
GitLab config outdated? ... no
Log directory writable? ... yes
Tmp directory writable? ... yes
Uploads directory setup correctly? ... yes
Init script exists? ... skipped (omnibus-gitlab has no init script)
Init script up-to-date? ... skipped (omnibus-gitlab has no init script)
projects have namespace: ...
21/3 ... yes
21/10 ... yes
21/21 ... yes
21/23 ... yes
21/24 ... yes
21/25 ... yes
44/35 ... yes
44/36 ... yes
44/37 ... yes
21/51 ... yes
44/52 ... yes
44/53 ... yes
51/56 ... yes
43/57 ... yes
20/58 ... yes
20/59 ... yes
46/65 ... yes
44/66 ... yes
20/67 ... yes
20/68 ... yes
20/69 ... yes
20/70 ... yes
20/71 ... yes
20/73 ... yes
51/74 ... yes
33/75 ... yes
33/76 ... yes
47/77 ... yes
33/78 ... yes
33/79 ... yes
33/80 ... yes
33/81 ... yes
33/82 ... yes
33/83 ... yes
33/84 ... yes
33/85 ... yes
33/86 ... yes
33/87 ... yes
33/88 ... yes
33/89 ... yes
33/90 ... yes
33/91 ... yes
33/92 ... yes
42/97 ... yes
24/115 ... yes
64/116 ... yes
120/117 ... yes
63/120 ... yes
120/122 ... yes
24/123 ... yes
32/125 ... yes
32/126 ... yes
32/127 ... yes
32/128 ... yes
32/129 ... yes
31/130 ... yes
74/131 ... yes
71/132 ... yes
71/133 ... yes
33/143 ... yes
74/144 ... yes
2/145 ... yes
2/146 ... yes
43/147 ... yes
83/153 ... yes
57/154 ... yes
57/155 ... yes
33/157 ... yes
83/159 ... yes
83/161 ... yes
83/163 ... yes
83/164 ... yes
74/166 ... yes
62/167 ... yes
33/168 ... yes
74/170 ... yes
74/171 ... yes
91/172 ... yes
44/173 ... yes
57/175 ... yes
57/176 ... yes
57/177 ... yes
57/178 ... yes
93/180 ... yes
93/181 ... yes
37/182 ... yes
66/183 ... yes
67/184 ... yes
67/185 ... yes
67/187 ... yes
33/188 ... yes
96/189 ... yes
33/190 ... yes
33/191 ... yes
33/192 ... yes
2/193 ... yes
37/194 ... yes
35/197 ... yes
51/198 ... yes
76/199 ... yes
6/201 ... yes
40/202 ... yes
40/203 ... yes
6/204 ... yes
66/205 ... yes
66/206 ... yes
43/207 ... yes
43/208 ... yes
82/210 ... yes
41/211 ... yes
43/212 ... yes
83/213 ... yes
52/214 ... yes
52/215 ... yes
81/216 ... yes
103/217 ... yes
103/218 ... yes
81/219 ... yes
94/220 ... yes
2/222 ... yes
105/224 ... yes
105/225 ... yes
105/227 ... yes
105/229 ... yes
34/230 ... yes
34/231 ... yes
34/233 ... yes
34/234 ... yes
34/235 ... yes
50/237 ... yes
50/238 ... yes
50/239 ... yes
50/240 ... yes
50/242 ... yes
33/243 ... yes
33/245 ... yes
33/246 ... yes
110/247 ... yes
110/248 ... yes
43/250 ... yes
120/251 ... yes
112/252 ... yes
112/253 ... yes
112/254 ... yes
105/255 ... yes
105/259 ... yes
105/263 ... yes
105/264 ... yes
60/265 ... yes
42/266 ... yes
42/267 ... yes
42/268 ... yes
42/269 ... yes
42/270 ... yes
42/271 ... yes
42/273 ... yes
42/274 ... yes
42/275 ... yes
42/276 ... yes
42/279 ... yes
42/280 ... yes
41/282 ... yes
41/283 ... yes
60/285 ... yes
60/286 ... yes
60/289 ... yes
60/290 ... yes
60/292 ... yes
60/293 ... yes
60/296 ... yes
60/297 ... yes
60/299 ... yes
60/300 ... yes
42/301 ... yes
43/302 ... yes
105/304 ... yes
41/305 ... yes
41/307 ... yes
62/308 ... yes
114/313 ... yes
79/314 ... yes
111/315 ... yes
92/316 ... yes
33/317 ... yes
81/318 ... yes
79/319 ... yes
119/320 ... yes
79/321 ... yes
119/322 ... yes
120/323 ... yes
35/324 ... yes
40/325 ... yes
71/326 ... yes
83/327 ... yes
4/328 ... yes
87/329 ... yes
6/330 ... yes
126/331 ... yes
63/332 ... yes
112/333 ... yes
82/334 ... yes
Redis version >= 2.8.0? ... yes
Ruby version >= 2.1.0 ? ... yes (2.3.1)
Your git bin path is "/opt/gitlab/embedded/bin/git"
Git version >= 2.7.3 ? ... yes (2.7.4)
Active users: 67
Checking GitLab ... Finished
Results of GitLab environment info
System information
System: Ubuntu 14.04
Current User: git
Using RVM: no
Ruby Version: 2.3.1p112
Gem Version: 2.6.6
Bundler Version:1.13.5
Rake Version: 10.5.0
Sidekiq Version:4.2.1
GitLab information
Version: 8.13.2-ee
Revision: 507ff23
Directory: /opt/gitlab/embedded/service/gitlab-rails
DB Adapter: PostgreSQL
DB Version: 9.2.18
URL: https://********
HTTP Clone URL: https://*******/some-group/some-project.git
SSH Clone URL: git@*******:some-group/some-project.git
Elasticsearch: no
Geo: no
Using LDAP: yes
Using Omniauth: no
GitLab Shell
Version: 3.6.6
Repository storage paths:
- default: /srv/storage/git-data/repositories
Hooks: /opt/gitlab/embedded/service/gitlab-shell/hooks/
Git: /opt/gitlab/embedded/bin/git
Possible fixes
(If you can, link to the line of code that might be responsible for the problem)