Allow failed LDAP binding to fallback onto native LDAP authentication user

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: Internal Code, Security
    • None
    • Server Security
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      If no LDAP bind user has been specified, we currently attempt to perform LDAP authorization queries without binding as a user. Many LDAP servers will disallow anonymous binds. We may want to reattempt queries which fail for this reason, binding with the same user and password as the authentication user, which will likely be authorized to perform queries for its own groups.

            Assignee:
            [DO NOT USE] Backlog - Security Team
            Reporter:
            Spencer Jackson
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: