Bug 161121 - nss_ldap should strip newline from ldap.secret
nss_ldap should strip newline from ldap.secret
Product: Fedora
Classification: Fedora
Component: nss_ldap (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Nalin Dahyabhai
Depends On:
  Show dependency treegraph
Reported: 2005-06-20 13:36 EDT by Pierre Ossman
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version: 235
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-09-09 11:01:23 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Pierre Ossman 2005-06-20 13:36:34 EDT
Description of problem:
If the password in ldap.secret is terminated by a newline, this newline gets
sent to the server causing the bind to fail. Since every operation in nss_ldap
now uses the privileged bind all users are blocked from logging in.

It's fairly common that editors add a trailing newline so nss_ldap really should
handle this gracefully.

Version-Release number of selected component (if applicable):

How reproducible:
Every time.

Steps to Reproduce:
1. Configure a rootbinddn with a ldap.secret
2. Try getent passwd
Actual results:
Only local entries are shown.

Expected results:
All entries, including those on the LDAP server, are shown.
Comment 1 Nalin Dahyabhai 2005-09-09 11:01:23 EDT
This was fixed upstream in nss_ldap 235, closing because Raw Hide currently
features nss_ldap-240-2.

Note You need to log in before you can comment on or make changes to this bug.