[Frog] AD authentication problems.
Just come up against something very strange recently with the AD authentication of our Frog box. We noticed that one student was logging into Frog as someone else in order to access the network home drive. Immediately we changed the victims password thinking that that was job done. Except that I then saw the student still logging in as the victim. I then tried logging in as the victim with their old password and indeed I was allowed in. I then thought I had made a mistake and changed the wrong users password. So I logged on to a computer (not Frog) as the victim with their old password and it failed, then I tried the new password and it worked.
I have since replicated this problem. By:
Created a test student in AD and set a password (A).
Create the matching user in Frog with random password and AD authentication ticked.
Log into Frog with password A. It works.
Reset the password (B) in AD and wait for AD replication to happen.
Log into Frog with password A. It still works.
Try a different browser and log into Frog with password A. It still works.
Try yet another browser and log into Frog with password A. It still works.
Log into Frog with password B. It works.
Log into Frog with password A. It now fails.
Has anyone else seen this?
Would someone else have the time to try this out to see if it is just us?