David Han created KNOX-3422:
-------------------------------
Summary: LDAP Proxy shouldn't create user from
gateway.ldap.bind.user config
Key: KNOX-3422
URL: https://issues.apache.org/jira/browse/KNOX-3422
Project: Apache Knox
Issue Type: Improvement
Components: Server
Affects Versions: 3.0.0
Reporter: David Han
Assignee: David Han
Fix For: 3.1.0
This user configured using the gateway.ldap.bind.user configuration is used to
bind against the LDAP Proxy. The gateway server currently creates a user in the
local LDAP using this configuration and the aliased password. The downside of
this approach is that there is currently no tracking for this user and no way
to automatically remove this user if the config changes nor rotate the
password. This user is also returned in search queries against the LDAP Proxy.
I propose creating a new authentication interceptor to manage this user
in-memory. This way the user won't be persisted and will automatically be
unable to authenticate if the configuration changes.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)