Bug 741999 - SASL/PLAIN binds do not work
SASL/PLAIN binds do not work
Product: 389
Classification: Community
Component: Directory Server (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Rich Megginson
Ben Levenson
Depends On:
Blocks: 389_1.3.0 690319 742054
  Show dependency treegraph
Reported: 2011-09-28 14:36 EDT by Simo Sorce
Modified: 2015-12-10 13:42 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 742054 (view as bug list)
Last Closed: 2015-12-10 13:42:23 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Simo Sorce 2011-09-28 14:36:19 EDT
I have tried to use a SASL/PLAIN bind in order to do binds with a user id that is not a DN.
Because SASL mappings can resolve an arbitrary uid into a DN I was hoping to use that to bind to a directory where anonymous searches are disabled (therefore the client can't use an anonymous bind to search the DN itself.

Unfortunately it appears the current DS code is not able to perform SASL/PLAIN authentication. Sasl mapping is incorrectly performed. It happens twice, the first time it properly maps the provided user name to a DN the second time it tries to map the found DN again as if it were a user name.

Rich says DS may no be able to properly provide SASL with callback to handle checking the password.
Comment 4 Martin Kosek 2012-01-04 08:20:56 EST
Upstream ticket:

Note You need to log in before you can comment on or make changes to this bug.