Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-3586

LDAP Manager DN and password are REQUIRED (security risk)

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Critical Critical
    • _unsorted
    • None
    • Platform: All, OS: Linux

      Using the 1.301 Hudson war under glassfish v2 with LDAP enabled results in
      Hudson supplying erroneous manager DN and manager password if these fields are
      left blank. When filling in the form all is well with the auto verification
      that taks place while one is filing in the form. However, after hitting the
      save button, then coming back to the LDAP configuration area of the Manage
      Hudson form, both the Manager DN and the Manager Password will have default
      values. The value are incorrect and seem to be drawn from the Authorization Matrix.

      The net result is that I have to fill in correct values despite my LDAP
      configuration not requiring BINDING prior to querying.

      I tried placing correct values in those two fields and saving the form then
      logging out then back in to make sure all is well then clearing those fields and
      saving the form. My intent was perhaps to reset some internal flag. This did
      not work. The same erroneous values popped back into the form upon navigating
      back to the form after having saved the form with the empty entries in those two
      fields.

      This is a security risk. I do not want to have to supply the admin DN and password.

            mindless Alan Harder
            jesterfred jesterfred
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: