Uploaded image for project: 'AMQ Broker'
  1. AMQ Broker
  2. ENTMQBR-1820

LDAPLoginModule should actively detect unauthenticated Bind requests

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • None
    • AMQ 7.1.0.GA
    • broker-core
    • None
    • Hide
      • Configure AMQ to use Active Directory in login.config
      • Issue a command such as:
      /var/opt/amq-broker/broker-7.2/bin/artemis queue stat --user juser
      

      The command may, or may not, prompt for a password. A network packet capture shows that the LDAP bind operation does not contain a password, but succeeds. Invalid user names do fail, as do empty user names.

      Show
      Configure AMQ to use Active Directory in login.config Issue a command such as: / var /opt/amq-broker/broker-7.2/bin/artemis queue stat --user juser The command may, or may not, prompt for a password. A network packet capture shows that the LDAP bind operation does not contain a password, but succeeds. Invalid user names do fail, as do empty user names.

      When issuing `artemis` commands, such as `producer` or `stat`, the user is not prompted for a password and the command runs successfully.

            rhn-support-jbertram Justin Bertram
            rhn-support-dgrove Doug Grove (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: