Uploaded image for project: 'Qpid'
  1. Qpid
  2. QPID-8127

[Broker-J][ACL] Allow case insensitive matching of group and user names in existing ACL

    XMLWordPrintableJSON

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Major
    • Resolution: Invalid
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Broker-J
    • Labels:
      None

      Description

      The current ACL rules matching functionality is case sensitive for user names and group names.

      When SimpleLdap authentication provider is configured and groups are fetched from LDAP as distinguished names, it is quite easy to make a mistake in group/user DN and put some of letter in wrong case as LDAP DN search is case-insensitive. Thus, users can specify some parts of DN in ACL using letters in wrong case.

      The debugging of such mistyped names can be time-consuming. IMHO, it make more sense to add ability into ACL implementation to match groups and user names in case insensitive way.

      The following link provides a good overview of case sensitivity of DN:
      http://ldapwiki.com/wiki/Distinguished%20Name%20Case%20Sensitivity

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                orudyy Alex Rudyy
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: