David Han created KNOX-3422:
-------------------------------

             Summary: LDAP Proxy shouldn't create user from 
gateway.ldap.bind.user config
                 Key: KNOX-3422
                 URL: https://issues.apache.org/jira/browse/KNOX-3422
             Project: Apache Knox
          Issue Type: Improvement
          Components: Server
    Affects Versions: 3.0.0
            Reporter: David Han
            Assignee: David Han
             Fix For: 3.1.0


This user configured using the gateway.ldap.bind.user configuration is used to 
bind against the LDAP Proxy. The gateway server currently creates a user in the 
local LDAP using this configuration and the aliased password. The downside of 
this approach is that there is currently no tracking for this user and no way 
to automatically remove this user if the config changes nor rotate the 
password. This user is also returned in search queries against the LDAP Proxy.

I propose creating a new authentication interceptor to manage this user 
in-memory. This way the user won't be persisted and will automatically be 
unable to authenticate if the configuration changes.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to