David Han created KNOX-3487:
-------------------------------
Summary: LDAP Proxy find all members of a role
Key: KNOX-3487
URL: https://issues.apache.org/jira/browse/KNOX-3487
Project: Apache Knox
Issue Type: Improvement
Components: Server
Affects Versions: 3.1.0
Reporter: David Han
Assignee: David Han
Fix For: 3.1.0
When role lookup is enabled on the LDAP Proxy, the LDAP Proxy should be able to
return all users that are assigned a role. E.g.,
{code}
ldapsearch -b 'ou=users,DC=proxy,DC=com' -s sub
'(memberOf=cn=rolename,ou=groups,dc=proxy,dc=com)' '*'
{code}
This would require calling the roles lookup service to get the mapped users and
groups for the given role. Then modifying the search filter to replace the
rolename with the users and groups.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)