Bug 535603 (RHQ-2281) - LDAP case insensitive authentication may lead to unwanted users
Summary: LDAP case insensitive authentication may lead to unwanted users
Keywords:
Status: CLOSED NOTABUG
Alias: RHQ-2281
Product: RHQ Project
Classification: Other
Component: Usability
Version: unspecified
Hardware: All
OS: All
medium
medium
Target Milestone: ---
: ---
Assignee: RHQ Project Maintainer
QA Contact:
URL: http://jira.rhq-project.org/browse/RH...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-07-30 18:07 UTC by Jay Shaughnessy
Modified: 2011-05-13 18:53 UTC (History)
1 user (show)

Fixed In Version: 2.4
Clone Of:
Environment:
LDAP
Last Closed: 2011-05-13 18:53:38 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 586435 0 low CLOSED Request case sensitive/insensitive option for LDAP Configuration 2021-02-22 00:41:40 UTC

Internal Links: 586435

Description Jay Shaughnessy 2009-07-30 18:07:00 UTC
LDAP authentication may be case insensitive whereas jon usernames are case sesnsitive.   So, a single LDAP username, say 'user1' may pass a login check for 'user1', 'User1', 'USER1', etc.  But, each of these variations will look like a different user to RHQ and each will ask to be registered separately upon successful LDAP authentication.

Perhaps for LDAP we should allow only one case-specific entry.  Meaning, if we invoke LDAP authentication, and it succeeds, check the RHQ db for the username in a case-insensitive way.  If there is a match, change the entered username to the existing entry and continue with the session.


Comment 1 Red Hat Bugzilla 2009-11-10 21:01:24 UTC
This bug was previously known as http://jira.rhq-project.org/browse/RHQ-2281


Comment 2 wes hayutin 2010-02-16 17:08:18 UTC
mass add of key word FutureFeature to help track

Comment 3 Simeon Pinder 2010-11-02 17:41:26 UTC
This issue should be closed. Is a duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=586435 which was already addressed/closed.

Comment 4 Simeon Pinder 2011-05-13 18:53:38 UTC
Closing as has already been addressed.


Note You need to log in before you can comment on or make changes to this bug.