Filter LDAP attribute queries in existing LDAP infrastructures

Bug #1102358 reported by Jose Castro Leon
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Fix Released
Undecided
Jose Castro Leon

Bug Description

When using existing LDAP infrastructure, the query retrieves much more information than needed in keystone.
It is extremely expensive when using AD as a backend (you receive much more useless information than the strictly required for keystone to run).

The main idea is sending the attributes in the ldap query so the server only replies the attributes needed.

Changed in keystone:
assignee: nobody → Jose Castro Leon (jose-castro-leon)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/20395

Changed in keystone:
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (master)

Reviewed: https://review.openstack.org/20395
Committed: http://github.com/openstack/keystone/commit/31b61e0769ac23ce508a59de96a82d9d52f124ef
Submitter: Jenkins
Branch: master

commit 31b61e0769ac23ce508a59de96a82d9d52f124ef
Author: Jose Castro Leon <email address hidden>
Date: Thu Jan 24 14:59:01 2013 +0100

    Query only attributes strictly required for keystone when using it
    with existing LDAP servers

    Fixes bug 1102358

    Change-Id: I7dd3ba1d66e0400fefb303f50dc84c145717a47e

Changed in keystone:
status: In Progress → Fix Committed
Thierry Carrez (ttx)
Changed in keystone:
milestone: none → grizzly-3
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in keystone:
milestone: grizzly-3 → 2013.1
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.