New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[WFCORE-5936] Ldap autentication using referrals fails on JDK 17 with ApacheDS #5123
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I believe you also need to update https://github.com/wildfly/wildfly-core/blob/19.0.0.Beta11/pom.xml#L156
Thanks @soul2zimate! Yes, I have not searched for poms... 😄 |
@rmartinc Thanks for working on this! It would be great to have a follow-up issue to add the test you mentioned. |
@fjuma @rmartinc Do we need com.sun.jndi.url.ldaps as well? For ldapsURLContextFactory. @jmesnil @jfdenise @pferraro FYI re this general topic for cloud, as a similar pattern of packages exists in jdk.naming.dns module with com.sun.jndi.dns and com.sun.jndi.url.dns. I don't know if that's relevant to how JGroups uses that package though. |
@bstansberry Very good catch! Yes, it is also needed... I see the same exception if the url returned in the referral if pointing to a ldaps port:
I'll submit a new PR tomorrow morning adding both exports in all the places. |
Now ldap and ldaps packages are added. Thanks @bstansberry! |
Core -> Full Integration Build 11654 outcome was FAILURE using a merge of e4cb0e9 Failed tests
|
Issue: https://issues.redhat.com/browse/WFCORE-5936
The elytron dir-context also needs exports for
com.sun.jndi.url.ldap
in order to follow referrals in JDK-17. There is a exception inorg.jboss.as.naming.context.ObjectFactoryBuilder
when trying to recreate the context for the referral now. Just adding the same exports that were added forcom.sun.jndi.ldap
in WFCORE-5438.@bstansberry Take a look when you have time. If you want it in another branch (26.x) just let me know.
@fjuma I was thinking about adding a referral and
referral-mode=follow
ldap realm test but I see they are on wildfly. I can create a followup JIRA for that if you think it's interesting.