Rally users locked until 3000-01-01
search cancel

Rally users locked until 3000-01-01

book

Article ID: 57603

calendar_today

Updated On:

Products

Rally On-Premise Rally SaaS

Issue/Introduction

When trying to log into Rally, the user may be sent an email indicating their account is locked until the year 3000. The Admin may also notice this when viewing the user's username in Setup.

Environment

Release:

 

Component:

Cause

Rally has put security measures in place for users who have not logged in for a period of a year or more (>=365 days) that will automatically lock the account resulting in an email stating that the account has been locked until 3000-01-01.

 

This will occur even when SSO is being used as the primary authentication system since this is an internal routine that runs independently of the authentication system in use.

Resolution

There are specific steps that need to be taken in order to unlock an account that has been inactive.

Below are the steps to take to re-enable the user account when using Rally authentication:

  1. A Subscription Admin will need to unlock the user account.

  2. The User should then use the "Forgot Your Password" link on the Rally login page to trigger a password reset email

    • The user should login as soon as possible to prevent the account from being locked again.

    • The process that locks accounts runs Saturday night at 11:30 PM Mountain time.

    • If the user is unable to login before the job runs, the account will be locked again and requires being unlocked by the Admin.

  3. Users should use the link provided in the email to reset their password

  4. Users will then need to login with their new Rally password

  5. Then immediately log out of Rally

  6. Log back in again

 

Since SSO users will be maintained/provisioned by their internal SSO team and not Rally, users can still login to Rally using SSO authentication when this occurs, BUT to clear the message the Subscription Administrator will need to "unlock" the user.  

  1. A Subscription Admin will need to unlock the user account.

  2. Users will then need to login with their SSO credentials