portals-jetspeed-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Michael Kearns (JIRA)" <jetspeed-...@portals.apache.org>
Subject [jira] Created: (JS2-562) LDAP attribute name comparison should be case-insensitive
Date Fri, 21 Jul 2006 10:37:14 GMT
LDAP attribute name comparison should be case-insensitive

                 Key: JS2-562
                 URL: http://issues.apache.org/jira/browse/JS2-562
             Project: Jetspeed 2
          Issue Type: Bug
          Components: Security
    Affects Versions: 2.0-FINAL
         Environment: Windows 2000 SP4, JDK1.5, Apache-DS 
            Reporter: Michael Kearns

When trying to authenticate against an LDAP server (in this case, Apache-DS from a seperate
installation), the authentication failed because the userPassword attribute was not found.

The attribute exists within LDAP, but the case is different (userpassword). While the schema
suggests the specified ID (userPassword) is correct, I believe  LDAP is supposedly case-insensitive,
and so ideally the attribute comparison should also be.

The change required is to the getAttribute method within org.apache.jetspeed.security.spi.impl.ldap.LdapUserCredentialDaoImpl,
replacing the equals() method with equalsIgnoreCase().

This message is automatically generated by JIRA.
If you think it was sent incorrectly contact one of the administrators: http://issues.apache.org/jira/secure/Administrators.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira


To unsubscribe, e-mail: jetspeed-dev-unsubscribe@portals.apache.org
For additional commands, e-mail: jetspeed-dev-help@portals.apache.org

View raw message