https://bz.apache.org/bugzilla/show_bug.cgi?id=70261

--- Comment #1 from tangent <[email protected]> ---
To help localise this crash issue, I've tried to reproduce the problem with the
2.4.69 build of mod_authnz_ldap.so to create a crash dump file, but have failed
to create one so far.

Unfortunately, I don't have a Windows Domain Controller to connect to for
testing, but instead established an instance of OpenLDAP on Linux Mint,
specifically configured to support LDAPS.

This is the basis of the Apache configuration I ended up testing with:

<Location /test>
  Authtype basic
  AuthName "LDAP Test"
  AuthBasicProvider ldap
  LDAPReferrals Off
  AuthLDAPBindDN "cn=admin,dc=lan"
  AuthLDAPBindPassword "xxx"
  AuthLDAPURL
"ldaps://ldapserver.lan:636/ou=People,dc=lan?uid?sub?(objectClass=inetOrgPerson)"
  Require valid-user
</Location>

Noting the Apache Lounge post detail at
https://www.apachelounge.com/viewtopic.php?p=44515, I believe the comment from
@Stanicher that 10 out of 14 of their AD users have no problem is particularly
significant, and to me suggests the module crash is caused by some difference
in the query content returned by AD for those users, and not the LDAP protocol
handling level per se.

Having said that, the authorization process is only checking user credentials,
rather than something more complex LDAP wise, e.g. matching entries, group
membership or some other attributes. However, my guess this problem is down to
the module handling of the data structures and content returned by the AD
server, particularly since crash error 0xC0000005 points to an access
violation.

The fact there's no problem with the 2.4.68 module rather confirms it's some
code regression in the later 2.4.69 version. In light of the above, could those
changes be reviewed?

-- 
You are receiving this mail because:
You are the assignee for the bug.
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to