Add LDAP tests to CI
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- csharp, docker
- Domain
- ci-cd, infrastructure, testing
Research direction
Start with src/libraries/Common/tests/System/DirectoryServices/LDAP.Configuration.xml and DirectoryServicesProtocolsTests.cs, then review the referenced docker commands and existing LDAP configurations. Determine which platform and TLS checkbox can be supported first, and verify that the selected LDAP tests run in CI with the required server setup and certificate validation.
Written by the indexing model from the issue text.
Description
The LDAP tests do not run in CI since there is infrastructure required to set up an LDAP server as explained in the various "docker run" commands and Active Directory section in https://github.com/dotnet/runtime/blob/main/src/libraries/Common/tests/System/DirectoryServices/LDAP.Configuration.xml.
This means every release we need to manually verify these tests.
Ideally, we add the following support:
- Support the OpenSsl (Linux and OsX) tests running by using the docker commands above and specify the environment variable so that the check for DirectoryServicesProtocolsTests.LdapConfigurationExists succeeds.
- Extend or add a new configuration based on "SLAPD OPENLDAP SERVER TLS" to enable the TLS handshake to test client and server certificate validation. See also https://github.com/dotnet/runtime/issues/60972 where
VerifyServerCertificate()doesn't work on Linux thus the need for an example + test. Currently, handshake is disabled in the XML instructions via "LDAP_TLS_VERIFY_CLIENT=never". High level steps include:- Use "LDAP_TLS_VERIFY_CLIENT=demand"
- Add support for adding the properly hashed client certificate to a directory and setting the
TrustedCertificatesDirectoryproperty to that directory. - Have the client trust the server certificate.
- Call
StartTransportLayerSecurity(null).
- Support the OpenSsl (ActiveDirectory - Windows) tests. This is more difficult than the Linux and may not be feasible.
- Dominant language
- C#
- Stars
- 18.3k
- Forks
- 5.6k
- PR merge metrics
- PR metrics pending
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dotnet/runtime
-
agentic-workflows untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
area-System.Reflection blocking-clean-ci-optional Known Build Error os-mac-os-x untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
area-CodeGen-coreclr untriaged
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
agentic-workflows untriaged
Difficulty 1/5 Under an hour Newbie friendliness 78/100
-
area-VM-meta-mono untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
:watch: Not Triaged 11.0 fundamentals/subsvc
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
dotnet/AspNetCore.Docs#37699 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
SubtitleEdit/subtitleedit#15108 · 1 comment ·
-
area/docs-content Bug pulumi/docs
Difficulty 1/5 1-3 hours Newbie friendliness 94/100
-
Create parent directories only after the containment check in InstallHelper.TryExtractToDirectory Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PowerShell/PSResourceGet#2056 ·