[
https://issues.apache.org/jira/browse/KNOX-3422?focusedWorklogId=1038064&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1038064
]
ASF GitHub Bot logged work on KNOX-3422:
----------------------------------------
Author: ASF GitHub Bot
Created on: 26/Aug/26 13:40
Start Date: 26/Aug/26 13:40
Worklog Time Spent: 10m
Work Description: handavid opened a new pull request, #1357:
URL: https://github.com/apache/knox/pull/1357
[KNOX-3422](https://issues.apache.org/jira/browse/KNOX-3422) - Create LDAP
Proxy bind user in-memory instead of in embedded LDAP
## What changes were proposed in this pull request?
The bind user created from the gateway configuration is now created
in-memory instead of being added to the embedded ldap server. This provides the
benefit of being able to rotate the user just by changing the configuration.
Previously, since the configured user is not tracked, there wasn't a way to
automatically rotate the user.
## How was this patch tested?
Unit test were updated and run.
## Integration Tests
LDAP proxy search workflow tests were updated to use the configured bind
user instead of a user in the remote LDAP.
A test was added to verify that anonymous bind does not work when the bind
user is configured.
## UI changes
no ui changes
Issue Time Tracking
-------------------
Worklog Id: (was: 1038064)
Remaining Estimate: 0h
Time Spent: 10m
> LDAP Proxy shouldn't create user from gateway.ldap.bind.user config
> -------------------------------------------------------------------
>
> Key: KNOX-3422
> URL: https://issues.apache.org/jira/browse/KNOX-3422
> Project: Apache Knox
> Issue Type: Improvement
> Components: Server
> Affects Versions: 3.0.0
> Reporter: David Han
> Assignee: David Han
> Priority: Major
> Fix For: 3.1.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> This user configured using the gateway.ldap.bind.user configuration is used
> to bind against the LDAP Proxy. The gateway server currently creates a user
> in the local LDAP using this configuration and the aliased password. The
> downside of this approach is that there is currently no tracking for this
> user and no way to automatically remove this user if the config changes nor
> rotate the password. This user is also returned in search queries against the
> LDAP Proxy.
> I propose creating a new authentication interceptor to manage this user
> in-memory. This way the user won't be persisted and will automatically be
> unable to authenticate if the configuration changes.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)