Project

General

Profile

Actions

Defect #8068

closed

LDAP Authentificaton doesn't verify certificate validity

Added by Siegfried Vogel about 13 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
LDAP
Target version:
-
Start date:
2011-04-05
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

Security-Bug:
LDAP Authentificaton doesn't verify certificate validity of the LDAP-server-certificate. Connection to the LDAP-Server with LDAPS is established, even if the server name in the certifitcate doesn't match or the certificate authority is not trustful.

Solution: If something is wrong with the certificate, or the certificate authority is not trustful, the connection to the LDAP-Server should be closed and any LDAP-Login should be disabled.


Related issues

Related to Redmine - Defect #24970: Net::LDAP::LdapError is deprecatedClosedJean-Philippe Lang

Actions
Related to Redmine - Patch #29606: Support self-signed LDAPS connectionsClosedJean-Philippe Lang

Actions
Has duplicate Redmine - Defect #8091: LDAP Authentificaton doesn't verify certificate validityClosed2011-04-05

Actions
Actions

Also available in: Atom PDF