Directory Kerberos
  1. Directory Kerberos
  2. DIRKRB-85

@CreateKdcServer should include searchBaseDn attribute

    Details

    • Type: Bug Bug
    • Status: Resolved
    • Priority: Critical Critical
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.0.0-M11
    • Component/s: None
    • Labels:
      None

      Description

      CreateKdcServer annotation doesn't contain searchBaseDn, so the KdcServer instance created by calling
      org.apache.directory.server.factory.ServerAnnotationProcessor.getKdcServer(DirectoryService, int) can't be used for domain other than "example.com".
      The KdcServer created from @CreateKdcServer configuration searches users always in "ou=users,dc=example,dc=com" (see to KdcServer constructor).

      For a LDAP server it's possible to change the search domain after the retrieving an instance from ServerAnnotationProcessor, but it doesn't work for the KdcServer, because the original value is already stored in a DirectoryPrincipalStore instance created by KdcServer.start() method.

        Activity

        Hide
        Emmanuel Lecharny added a comment -

        We do have a SearchBaseDn attribute available : http://svn.apache.org/r1445865

        Show
        Emmanuel Lecharny added a comment - We do have a SearchBaseDn attribute available : http://svn.apache.org/r1445865

          People

          • Assignee:
            Emmanuel Lecharny
            Reporter:
            Josef Cacek
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development