[jboss-jira] [JBoss JIRA] (ELY-863) Elytron ldap-realm allows access with empty password

Jan Kalina (JIRA) issues at jboss.org
Tue Jan 10 08:07:00 EST 2017


Jan Kalina created ELY-863:
------------------------------

             Summary: Elytron ldap-realm allows access with empty password
                 Key: ELY-863
                 URL: https://issues.jboss.org/browse/ELY-863
             Project: WildFly Elytron
          Issue Type: Bug
          Components: Realms
    Affects Versions: 1.1.0.Beta17
            Reporter: Jan Kalina
            Assignee: Jan Kalina
            Priority: Blocker


An empty password is treated as an anonymous login by some LDAP servers (e.g. by Microsoft Active Directory). In case when Elytron ldap-realm is configured for that type of LDAP server then access with empty password to secured web resource guarded by that ldap-realm is always granted.

There should be some attribute for configuring whether empty password should be accepted by ldap-realm.

Similar issue occurs in previous versions of application server, see:
* https://bugzilla.redhat.com/show_bug.cgi?id=901251
* https://bugzilla.redhat.com/show_bug.cgi?id=885569



--
This message was sent by Atlassian JIRA
(v7.2.3#72005)


More information about the jboss-jira mailing list