Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-644

Limit/page results of LDAP group membership search

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 0.6.0
    • 0.10.0
    • Server
    • None

    Description

      Some users are finding that they have >1000 groups that would be returned given how Knox currently implements group lookup. ActiveDirectory currently limits search results to 1000 items and this causes failures that require workarounds at the client side. Ideally Knox's LDAP group search implementation would either limit/filter the results or page the result set that are unavoidably large.

      Attachments

        1. KNOX-644.patch
          28 kB
          Kevin Risden
        2. create_groups_ldif.py
          0.7 kB
          Kevin Risden
        3. paging.patch
          34 kB
          Kevin Risden
        4. ad_setup.ps1
          0.7 kB
          Kevin Risden
        5. KNOX-644-paging.patch
          10 kB
          Kevin Risden

        Issue Links

          Activity

            People

              krisden Kevin Risden
              kminder Kevin Minder
              Votes:
              3 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: