Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Apache: Bugs

[Bug 47521] mod_auth fails to continue when mod_authnz_ldap fails to contact a server

 

 

Apache bugs RSS feed   Index | Next | Previous | View Threaded


bugzilla at apache

Nov 20, 2009, 7:59 AM

Post #1 of 2 (277 views)
Permalink
[Bug 47521] mod_auth fails to continue when mod_authnz_ldap fails to contact a server

https://issues.apache.org/bugzilla/show_bug.cgi?id=47521

--- Comment #5 from Maxim Khitrov <mkhitrov [at] gmail> 2009-11-20 07:59:44 UTC ---
(In reply to comment #4)
> (In reply to comment #3)
> > It was my understanding that mod_authn_alias would try each authentication
> > method in order until a username match was found. It would seem to me that
> > failing to connect to an LDAP server would imply that a username could not be
> > found.
>
> It was intended to continue looking after a failed authentication. A service
> down condition wasn't ever really considered. Basically it comes down to
> whether or not "service down" == "failed authentication". I can certainly see
> a case for it.

I just ran into this problem. In my case, I have two domain controllers and
would like mod_authn_alias to try the second controller if it isn't able to
contact the first.

In this setup, the user database on both servers is identical, so "service
down" is really the only condition in which I would expect the next
authentication method to be attempted. As it stands, if the first server is
down a connection to the second isn't made.

Perhaps it is worth adding some sort of on-error directive (or another
parameter to AuthBasicProvider) that would specify how error conditions other
than "failed authentication" should be handled with a choice of "break" and
"continue".

--
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: bugs-unsubscribe [at] httpd
For additional commands, e-mail: bugs-help [at] httpd


bugzilla at apache

Nov 20, 2009, 9:23 AM

Post #2 of 2 (259 views)
Permalink
[Bug 47521] mod_auth fails to continue when mod_authnz_ldap fails to contact a server [In reply to]

https://issues.apache.org/bugzilla/show_bug.cgi?id=47521

--- Comment #6 from Maxim Khitrov <mkhitrov [at] gmail> 2009-11-20 09:22:56 UTC ---
(In reply to comment #5)
> (In reply to comment #4)
> > (In reply to comment #3)
> > > It was my understanding that mod_authn_alias would try each authentication
> > > method in order until a username match was found. It would seem to me that
> > > failing to connect to an LDAP server would imply that a username could not be
> > > found.
> >
> > It was intended to continue looking after a failed authentication. A service
> > down condition wasn't ever really considered. Basically it comes down to
> > whether or not "service down" == "failed authentication". I can certainly see
> > a case for it.
>
> I just ran into this problem. In my case, I have two domain controllers and
> would like mod_authn_alias to try the second controller if it isn't able to
> contact the first.

Just found out that you can specify multiple servers in the ldap://... uri, so
I guess this issue no longer applies to me.

--
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: bugs-unsubscribe [at] httpd
For additional commands, e-mail: bugs-help [at] httpd

Apache bugs RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.