Sandor Molnar created KNOX-3497:
-----------------------------------

             Summary: LdapProxyBackend does not resolve credential-store 
aliases for bind/system password
                 Key: KNOX-3497
                 URL: https://issues.apache.org/jira/browse/KNOX-3497
             Project: Apache Knox
          Issue Type: Improvement
          Components: Server
    Affects Versions: 3.0.0
            Reporter: Sandor Molnar
            Assignee: Sandor Molnar
             Fix For: 3.1.0


{{LdapProxyBackend}} reads the AD service-account password as a literal string 
and never resolves credential-store aliases:
 * {{LdapProxyBackend.java:158-161}} - {{bindPassword = 
config.get("bindPassword") / config.get("systemPassword");}} value passed 
verbatim to {{setCredentials()}} (lineĀ 282).

 * No {{AliasService}} reference anywhere in the class or its factory.

 * Upstream config ({{{}GatewayConfigImpl.getLDAPInterceptorConfig{}}}) is a 
plain prefix scan with no alias expansion; the only alias-aware LDAP calls 
({{{}KnoxLDAPServerManager.start{}}}, {{{}resolveSslKeystorePassword{}}}) are 
off this path.

{*}Impact{*}: An alias reference in 
{{gateway.ldap.interceptor.<name>.bindPassword/.systemPassword}} is used as the 
literal password, so the AD bind fails. Passwords can only be stored in 
cleartext config today.

{*}Fix{*}: Resolve aliases for the bind/system password on the backend path (in 
{{LdapProxyBackend.init()}} or when the interceptor config is assembled), 
preserving literal values for back-compat.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to