[
https://issues.jboss.org/browse/SECURITY-711?page=com.atlassian.jira.plug...
]
Anil Saldhana commented on SECURITY-711:
----------------------------------------
Peter - I am unsure if you have been following on the latest security work we are doing
for PicketLink v3. There is a lot of LDAP related stuff ongoing.
http://lists.jboss.org/pipermail/security-dev/
To subscribe:
https://lists.jboss.org/mailman/listinfo/security-dev
We hope you can become a valuable contributor. :)
Regarding this JIRA issue, I am going to sit on it until we get AD testing in place.
LdapExtAdLoginModule proposal for inclusion
-------------------------------------------
Key: SECURITY-711
URL:
https://issues.jboss.org/browse/SECURITY-711
Project: PicketBox
Issue Type: Patch
Security Level: Public(Everyone can see)
Components: PicketBox, Security SPI
Affects Versions: PicketBox_4_0_14.Final
Environment: jboss7, active directory authentication
Reporter: Péter Radics
Assignee: Anil Saldhana
Priority: Minor
Labels: LdapExtLoginModule, active-directory, security
Attachments: picketbox-r359-LdapExtLoginModule.patch,
picketbox-r362-LdapExtAdLoginModule.patch,
picketbox-r363-LdapExtAdLoginModule-with-history.patch
Original Estimate: 1 week
Remaining Estimate: 1 week
Please consider including the attached LdapExtAdLoginModule into the official release.
This login module is based on r362 of LdapExtLoginModule, but it's better suited for
deeply nested Active Directory domains: it only uses one search for the userDN then
it's resolving the roles recursively by querying attributes on DNs only. (as a
side-effect, it doesn't trigger AS7-5737)
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see:
http://www.atlassian.com/software/jira