LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > LDAP Authentication Issue

Reply
 
Thread Tools Display Modes
  #1  
Old 07-09-2008, 06:06 AM
dcb dcb is offline
New Member
 
Join Date: Jul 2008
Posts: 3
Default LDAP Authentication Issue

We are using the Enterprise version (3.3.15) on Slackware 12 (32bit).
We've setup a LDAP realm that seems to work properly. I mean, if you give the correct user/pass it all works as it is supposed to. But the real problem is when you give a bogus user/pass. Instead of asking for the user/pass again it will give you the URI requested. Of course on the next request it will ask again for user/pass, you can give a bogus one again and go on like that forever, gaining access to areas that are supposed to be protected.
Now I've checked and this happens only when the "Required" field in the context config is left empty (I tried putting there valid-user, with no effect). But the documentation says: "If it is not specified, all valid users can access this resource.", or a bogus user/pass combination shouldn't be considered valid.
Reply With Quote
  #2  
Old 07-09-2008, 02:32 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
We will look into this issue. Thanks for the bug report.
Reply With Quote
  #3  
Old 07-11-2008, 12:45 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
Can you please turn on debug logging by change "DebugLevel" to "HIGH", then try one request and send the error.log to bug@litespeed...
Reply With Quote
  #4  
Old 07-15-2008, 11:20 AM
dcb dcb is offline
New Member
 
Join Date: Jul 2008
Posts: 3
Do you need the entire log file? even for only 40 seconds it still has 10MB.
Reply With Quote
  #5  
Old 07-15-2008, 11:26 AM
dcb dcb is offline
New Member
 
Join Date: Jul 2008
Posts: 3
the relevant LDAP related lines seem to be:
2008-07-15 14:09:24.898 [DEBUG] [*.*.*.*:34457-0#admin] Assigned ID: 2 to 'ldap://[removed.host]/dc=manager,dc=com???(&(objectClass=person)(uid=fwe rfwerf))'
2008-07-15 14:09:24.898 [DEBUG] [*.*.*.*:34457-0#admin] checkAuthentication() return -1
2008-07-15 14:09:24.898 [DEBUG] [*.*.*.*:34457-0#admin] processNewReq() return 0.

If that's not enough I can try to grep the log by the name of the virtual host, that must reduce it a lot as another virtual host is producing the bulk of the traffic.
Reply With Quote
  #6  
Old 07-15-2008, 11:31 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
You can grep the log by the IP.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 11:30 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.