[
https://issues.apache.org/jira/browse/KNOX-3422?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109108#comment-18109108
]
ASF subversion and git services commented on KNOX-3422:
-------------------------------------------------------
Commit c7761322d5534f5807aa1967727e8887106cf107 in knox's branch
refs/heads/master from David Han
[ https://gitbox.apache.org/repos/asf?p=knox.git;h=c7761322d ]
KNOX-3422: Ldap Proxy used in-memory bind user (#1357)
* KNOX-3422: Ldap Proxy used in-memory bind user
The bind user created from the gateway configuration is now created
in-memory instead of being added to the embedded ldap server. This
provides the benefit of being able to rotate the user just by changing
the configuration. Previously, since the configured user is not tracked,
there wasn't a way to automatically rotate the user.
* throw LdapAuthenticationException
> LDAP Proxy shouldn't create user from gateway.ldap.bind.user config
> -------------------------------------------------------------------
>
> Key: KNOX-3422
> URL: https://issues.apache.org/jira/browse/KNOX-3422
> Project: Apache Knox
> Issue Type: Improvement
> Components: Server
> Affects Versions: 3.0.0
> Reporter: David Han
> Assignee: David Han
> Priority: Major
> Fix For: 3.1.0
>
> Time Spent: 1h
> Remaining Estimate: 0h
>
> This user configured using the gateway.ldap.bind.user configuration is used
> to bind against the LDAP Proxy. The gateway server currently creates a user
> in the local LDAP using this configuration and the aliased password. The
> downside of this approach is that there is currently no tracking for this
> user and no way to automatically remove this user if the config changes nor
> rotate the password. This user is also returned in search queries against the
> LDAP Proxy.
> I propose creating a new authentication interceptor to manage this user
> in-memory. This way the user won't be persisted and will automatically be
> unable to authenticate if the configuration changes.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)