Details

    • Type: Improvement Improvement
    • Status: Closed Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: LDAP-1.2.1
    • Component/s: LDAP
    • Labels:
      None
    • Number of attachments :
      0

      Issue Links

        Activity

        Hide
        Julien HENRY added a comment -

        See http://docs.oracle.com/javase/jndi/tutorial/ldap/security/simple.html

        The protocol automatically converts the authentication to "none" if a password is not supplied.

        Show
        Julien HENRY added a comment - See http://docs.oracle.com/javase/jndi/tutorial/ldap/security/simple.html The protocol automatically converts the authentication to "none" if a password is not supplied.
        Hide
        Evgeny Mandrikov added a comment -

        And in case of server with enabled anonymous access, this will lead to a successful authentication (we check password by using bind).

        Show
        Evgeny Mandrikov added a comment - And in case of server with enabled anonymous access, this will lead to a successful authentication (we check password by using bind).
        Hide
        Julien HENRY added a comment -

        As highlighted by Evgeny the problem only occurs with simple authentication. With the fix authentication will be prevented when password is blank AND using simple authentication.

        Show
        Julien HENRY added a comment - As highlighted by Evgeny the problem only occurs with simple authentication. With the fix authentication will be prevented when password is blank AND using simple authentication.
        Hide
        Freddy Mallet added a comment -

        Manually tested !

        Show
        Freddy Mallet added a comment - Manually tested !
        Hide
        Julien HENRY added a comment -

        IT added

        Show
        Julien HENRY added a comment - IT added

          People

          • Assignee:
            Julien HENRY
            Reporter:
            Freddy Mallet
          • Votes:
            1 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: