Project

General

Profile

Actions

Bug #8439

closed

Trailing whitespace on username not respected in LDAP filter

Added by Jim Pingle about 6 years ago. Updated almost 6 years ago.

Status:
Not a Bug
Priority:
Low
Assignee:
Category:
User Manager / Privileges
Target version:
-
Start date:
04/06/2018
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:
All

Description

When a user attempts to authenticate with LDAP, if they incorrectly enter their username with a trailing space the LDAP filter still successfully finds and validates the user. Local auth and RADIUS both reject this case, so LDAP should handle it consistently if possible.

This can cause a quirk with OpenVPN where the user will still be considered logged in with the trailing space as a part of their username, which can lead to failing to match a CSC/Override or other weirdness.

Actions

Also available in: Atom PDF