Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Ldap whoami switch #1317

Closed
wants to merge 5 commits into from
Closed

feat: Ldap whoami switch #1317

wants to merge 5 commits into from

Conversation

NiceRath
Copy link

@NiceRath NiceRath commented Jul 7, 2023

Greetings!

This PR adds a config-flag to disable the LDAP-WhoAmI checks that seem to break LDAP-integrations for some users: #1238

- Rath

@fiftin
Copy link
Collaborator

fiftin commented Jul 7, 2023

Hi @NiceRath

Will merge soon. Thank you!

@ansibleguy
Copy link
Contributor

@fiftin Just a reminder - 'soon' (;

@NiceRath
Copy link
Author

Yes - would be nice to have this merged.
This is a breaking issue if you depend on one of the affected LDAP providers.

@NiceRath
Copy link
Author

NiceRath commented Sep 25, 2023

@fiftin If you dislike the config-switch you could also just remove the 'WhiAmI' check completely.
Can't see the need for it after the LDAP server accepted the user authentication..

@Ye-Min-Tun
Copy link

Are there any ways to use encryption for ldap_bindpassword in config.json?
Is only plain text allowed currently? @NiceRath @ansibleguy

@NiceRath
Copy link
Author

@Ye-Min-Tun No - but that has nothing to do with this PR/change.
Also: The bind user only needs read access to the LDAP directory. It does not need to have any special privileges.
Make sure to set the mode of he config.json to 0600 - so only the semaphore user can access/read it.

@NiceRath
Copy link
Author

It seems the maintainer has no plan to implement this fix.. so I'll close the PR.
The project is unusable for me at this point

@NiceRath NiceRath closed this Jan 31, 2024
@snk26
Copy link

snk26 commented Feb 1, 2024

@fiftin Добавь, пожалуйста, эту опцию. Мы все еще ждем! Google LDAP не пускает с WhoAmi.

@fiftin
Copy link
Collaborator

fiftin commented Feb 1, 2024

@snk26 Я не спец в LDAP, если я вообще удаю эту проверку, это на что-то повлияет?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants