Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-644

Limit/page results of LDAP group membership search

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 0.6.0
    • Fix Version/s: 0.10.0
    • Component/s: Server
    • Labels:
      None

      Description

      Some users are finding that they have >1000 groups that would be returned given how Knox currently implements group lookup. ActiveDirectory currently limits search results to 1000 items and this causes failures that require workarounds at the client side. Ideally Knox's LDAP group search implementation would either limit/filter the results or page the result set that are unavoidably large.

        Attachments

        1. KNOX-644-paging.patch
          10 kB
          Kevin Risden
        2. ad_setup.ps1
          0.7 kB
          Kevin Risden
        3. paging.patch
          34 kB
          Kevin Risden
        4. create_groups_ldif.py
          0.7 kB
          Kevin Risden
        5. KNOX-644.patch
          28 kB
          Kevin Risden

          Issue Links

            Activity

              People

              • Assignee:
                risdenk Kevin Risden
                Reporter:
                kminder Kevin Minder
              • Votes:
                3 Vote for this issue
                Watchers:
                8 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: