-
Bug
-
Resolution: Done
-
Blocker
-
7.1.0.DR9
-
None
An empty password is treated as an anonymous login by some LDAP servers (e.g. by Microsoft Active Directory). In case when Elytron ldap-realm is configured for that type of LDAP server then access with empty password to secured web resource guarded by that ldap-realm is always granted.
There should be some attribute for configuring whether empty password should be accepted by ldap-realm.
Similar issue occurs in previous versions of application server, see:
- is cloned by
-
ELY-850 Elytron ldap-realm allows access with empty password
- Resolved
-
WFLY-7866 Elytron ldap-realm allows access with empty password
- Closed
- is incorporated by
-
JBEAP-8259 Upgrade to Elytron Subsystem 1.0.0.Alpha20
- Closed