apache / apache/cloudstack

Unable to create another ldap Account if another account is linked to ldap group in the same domain

Open
#8,732 2 comments 0 reactions 0 assignees Claimed by @DaanHoogland View on GitHub
component:LDAP Severity:Minor status:needs-investigation
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

##### ISSUE TYPE

* Bug Report

##### COMPONENT NAME

~~~
ldap
~~~

##### CLOUDSTACK VERSION
~~~
4.19
~~~

##### CONFIGURATION

Advanced Networking, Domain tree with multiple subdomains

##### OS / ENVIRONMENT

RHEL 9.3
VMware 8.0c (8.0.0.3)
LDAP 389 Directory Server

##### SUMMARY

If I create ldap account in domain with ldapCreateAccount, then link this account to ldap group with linkAccountToLdap, I'm not able to create another account in the same domain. I got error:
CloudStack error: HTTP 534 response from CloudStack
{
"createaccountresponse": {
"cserrorcode": 9999,
"errorcode": 534,
"errortext": "No LDAP user exists with the username of test_user",
"uuidList": []
}
}

If I create multiple accounts with ldapCreateAccount first, then I'm able to link all these accounts to ldap groups with linkAccountToLdap. But again, not able to create any other new ldap accounts

##### STEPS TO REPRODUCE

~~~
cs --post ldapCreateAccount username=test_admin account='Test admins' accounttype=2 domainid=6xxxxxx0e-d170-48ea-a9bf-90fexxxxx122
cs --post linkAccountToLdap account='Test Admins' accounttype=2 domainid=6xxxxxx0e-d170-48ea-a9bf-90fexxxxx122 ldapdomain='cn=test admins,cn=test,ou=groups,dc=my,dc=domain,dc=com' type=GROUP
cs --post ldapCreateAccount username=test_users account='Test users' accounttype=0 domainid=6xxxxxx0e-d170-48ea-a9bf-90fexxxxx122
~~~

##### EXPECTED RESULTS

~~~
Create another account in ldap and link it to another ldap group
~~~

##### ACTUAL RESULTS

~~~
CloudStack error: HTTP 534 response from CloudStack
{
"createaccountresponse": {
"cserrorcode": 9999,
"errorcode": 534,
"errortext": "No LDAP user exists with the username of test_user",
"uuidList": []
}
}
~~~

Contributor guide

Open the contributing guide

Research direction

Reproduce the issue using ldapCreateAccount followed by linkAccountToLdap in the described CloudStack 4.19 LDAP configuration, then inspect the LDAP account-creation and group-linking entry points. Done means a second account can be created in the same domain and linked to another LDAP group without the HTTP 534 error; pull request #13945 is already open.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.