Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[BUG] Apache 2.2 ldap authzn module behaviour wrong

From: Aki Tuomi <cmouse(at)youzen.ext.b2.fi>
Date: Thu Nov 29 2007 - 07:44:49 EST


Summary
 The LDAP authentication module does not send 403 when user successfully authenticates to the system but is not authorized to see content.

Steps to reproduce
 Configure LDAP authentication. Setup directory with   require ldap-user username

Expected behaviour
 After providing correct credentials, a 403 should occur if username does not match.

What happens
 User is given 401, and asked to reauthenticate.

Version and other information
 Server version: Apache/2.2.3
 Server built: Jun 17 2007 20:24:06  

 debian_version 4.0

 LDAP server is Microsoft Active Directory  AuthzLDAPAuthoritative is On

Aki Tuomi

-- 
To UNSUBSCRIBE, email to debian-apache-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Thu Nov 29 08:37:35 2007
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 02:59:04 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library