Uploaded image for project: 'Zeppelin'
  1. Zeppelin
  2. ZEPPELIN-3526

Zeppelin auth mechanisms (LDAP or password based) should be mutually exclusive

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 0.7.3
    • 0.8.0
    • None
    • None

    Description

      Problem:
      When any external authentication (like LDAP/AD) is enabled for Zeppelin, the default password-based authentication could still be configured in addition to that. This makes space for backdoor in Zeppelin where user can still get in using the local username/password.

      Workaround:
      Currently, the workaround is to make sure that [users] is removed from shiro.ini to stop anyone logging using local username/password.

      Proposed Solution:
      Zeppelin shouldn't allow specifying [users] section in shiro.ini when it is configured to authenticate with LDAP/AD.

      Attachments

        Activity

          People

            prabhjyotsingh Prabhjyot Singh
            prabhjyotsingh Prabhjyot Singh
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: