Sandor Molnar created KNOX-3497:
-----------------------------------
Summary: LdapProxyBackend does not resolve credential-store
aliases for bind/system password
Key: KNOX-3497
URL: https://issues.apache.org/jira/browse/KNOX-3497
Project: Apache Knox
Issue Type: Improvement
Components: Server
Affects Versions: 3.0.0
Reporter: Sandor Molnar
Assignee: Sandor Molnar
Fix For: 3.1.0
{{LdapProxyBackend}} reads the AD service-account password as a literal string
and never resolves credential-store aliases:
* {{LdapProxyBackend.java:158-161}} - {{bindPassword =
config.get("bindPassword") / config.get("systemPassword");}} value passed
verbatim to {{setCredentials()}} (lineĀ 282).
* No {{AliasService}} reference anywhere in the class or its factory.
* Upstream config ({{{}GatewayConfigImpl.getLDAPInterceptorConfig{}}}) is a
plain prefix scan with no alias expansion; the only alias-aware LDAP calls
({{{}KnoxLDAPServerManager.start{}}}, {{{}resolveSslKeystorePassword{}}}) are
off this path.
{*}Impact{*}: An alias reference in
{{gateway.ldap.interceptor.<name>.bindPassword/.systemPassword}} is used as the
literal password, so the AD bind fails. Passwords can only be stored in
cleartext config today.
{*}Fix{*}: Resolve aliases for the bind/system password on the backend path (in
{{LdapProxyBackend.init()}} or when the interceptor config is assembled),
preserving literal values for back-compat.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)