[ https://issues.apache.org/jira/browse/KARAF-2140?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Jean-Baptiste Onofré updated KARAF-2140: ---------------------------------------- Fix Version/s: (was: 2.3.6) (was: 2.4.0) 2.3.7 2.4.1 3.0.2 > Add an explicit allowEmptyPasswords to the LDAPLoginModule defaulting to false > ------------------------------------------------------------------------------ > > Key: KARAF-2140 > URL: https://issues.apache.org/jira/browse/KARAF-2140 > Project: Karaf > Issue Type: Improvement > Components: karaf-core > Reporter: Guillaume Nodet > Assignee: Jean-Baptiste Onofré > Fix For: 4.0.0, 3.0.2, 2.4.1, 2.3.7 > > > LDAP servers usually allow anonymous identification by sending an empty > passwords. The roles checks should guard against this, but a specific option > would close any risk. -- This message was sent by Atlassian JIRA (v6.2#6252)