smolnar82 opened a new pull request, #732:
URL: https://github.com/apache/knox/pull/732
## What changes were proposed in this pull request?
Added alias service lookup when dealing with LDAP system passwords in a form
of `${ALIAS=value}`.
## How was this patch tested?
Added new unit test case to cover this improvement, and ran manual testing:
Added the following parameters in the KnoxSSO topology:
```
<param>
<name>main.ldapRealm.contextFactory.systemUsername</name>
<value>uid=admin,ou=people,dc=hadoop,dc=apache,dc=org</value>
</param>
<param>
<name>main.ldapRealm.contextFactory.systemPassword</name>
<value>${ALIAS=ldapsystempassword}</value>
</param>
```
Saved `ldapsystempassword`:
```
$ bin/knoxcli.sh create-alias ldapsystempassword --value admin-password
--cluster knoxsso
ldapsystempassword has been successfully created.
```
Prior to my changes; I got this:
```
$ bin/knoxcli.sh system-user-auth-test --cluster knoxsso
org.apache.shiro.authc.AuthenticationException: LDAP authentication failed.
[LDAP: error code 49 - INVALID_CREDENTIALS: Bind failed: ERR_229 Cannot
authenticate user uid=admin,ou=people,dc=hadoop,dc=apache,dc=org]
For more information use --d for debug output.
```
After my changes:
```
$ bin/knoxcli.sh system-user-auth-test --cluster knoxsso
System password is stored as an alias ldapsystempassword; looking it up...
System LDAP Bind successful.
```
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]