spring-projects / spring-projects/spring-security

SEC-1963: ActiveDirectoryLdapAuthenticationProvider: flag binary attributes

Open
#2,188 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: ldap type: enhancement type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Mark Rigby-Jones (Migrated from SEC-1963) said:

JNDI is not able to correctly detect binary attributes in Active Directory, leading to some attributes (such as the SID and GUID) to be incorrectly transferred in text mode, leading to corruption for certain values. A fix for this is to add an additional item to the environment in bindAsUser(...):

env.put("java.naming.ldap.attributes.binary", "objectGUID objectSid");

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the bindAsUser(...) entry point in the Spring Security source and inspect how its JNDI environment is assembled. Verify the Active Directory binary-attribute handling for objectGUID and objectSid, then check the relevant existing authentication coverage; done means those values are not transferred in text mode or corrupted.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authentication, backend
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.