Skip to content

Instantly share code, notes, and snippets.

@khosrow
Last active August 29, 2015 14:11
Show Gist options
  • Save khosrow/cc6640cad9275a2cd041 to your computer and use it in GitHub Desktop.
Save khosrow/cc6640cad9275a2cd041 to your computer and use it in GitHub Desktop.
OpenLDAP Chaining Bug - ITS #8005
Dec 16 21:33:23 ldap3-dev slapd[7782]: slap_listener_activate(8):
Dec 16 21:33:23 ldap3-dev slapd[7782]: >>> slap_listener(ldap:///)
Dec 16 21:33:23 ldap3-dev slapd[7782]: conn=1001 fd=15 ACCEPT from IP=127.0.0.1:39181 (IP=0.0.0.0:389)
Dec 16 21:33:23 ldap3-dev slapd[7782]: connection_get(15)
Dec 16 21:33:23 ldap3-dev slapd[7782]: connection_get(15): got connid=1001
Dec 16 21:33:23 ldap3-dev slapd[7782]: connection_read(15): checking for input on id=1001
Dec 16 21:33:23 ldap3-dev slapd[7782]: op tag 0x60, time 1418765603
Dec 16 21:33:23 ldap3-dev slapd[7782]: conn=1001 op=0 do_bind
Dec 16 21:33:23 ldap3-dev slapd[7782]: >>> dnPrettyNormal: <cn=admin,dc=example,dc=org>
Dec 16 21:33:23 ldap3-dev slapd[7782]: <<< dnPrettyNormal: <cn=admin,dc=example,dc=org>, <cn=admin,dc=example,dc=org>
Dec 16 21:33:23 ldap3-dev slapd[7782]: conn=1001 op=0 BIND dn="cn=admin,dc=example,dc=org" method=128
Dec 16 21:33:23 ldap3-dev slapd[7782]: do_bind: version=3 dn="cn=admin,dc=example,dc=org" method=128
Dec 16 21:33:23 ldap3-dev slapd[7782]: send_ldap_result: conn=1001 op=0 p=3
Dec 16 21:33:23 ldap3-dev slapd[7782]: send_ldap_result: err=53 matched="" text="unauthenticated bind (DN with no password) disallowed"
Dec 16 21:33:23 ldap3-dev slapd[7782]: send_ldap_response: msgid=1 tag=97 err=53
Dec 16 21:33:23 ldap3-dev slapd[7782]: conn=1001 op=0 RESULT tag=97 err=53 text=unauthenticated bind (DN with no password) disallowed
Dec 16 21:33:23 ldap3-dev slapd[7782]: do_bind: v3 anonymous bind
Dec 16 21:33:23 ldap3-dev slapd[7782]: connection_get(15)
Dec 16 21:33:23 ldap3-dev slapd[7782]: connection_get(15): got connid=1001
Dec 16 21:33:23 ldap3-dev slapd[7782]: connection_read(15): checking for input on id=1001
Dec 16 21:33:23 ldap3-dev slapd[7782]: op tag 0x42, time 1418765603
Dec 16 21:33:23 ldap3-dev slapd[7782]: conn=1001 op=1 do_unbind
Dec 16 21:33:23 ldap3-dev slapd[7782]: conn=1001 op=1 UNBIND
Dec 16 21:33:23 ldap3-dev slapd[7782]: connection_close: conn=1001 sd=15
Dec 16 21:33:23 ldap3-dev slapd[7782]: conn=1001 fd=15 closed
Dec 16 21:33:36 ldap3-dev slapd[7782]: slap_listener_activate(8):
Dec 16 21:33:36 ldap3-dev slapd[7782]: >>> slap_listener(ldap:///)
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 fd=15 ACCEPT from IP=127.0.0.1:39183 (IP=0.0.0.0:389)
Dec 16 21:33:36 ldap3-dev slapd[7782]: connection_get(15)
Dec 16 21:33:36 ldap3-dev slapd[7782]: connection_get(15): got connid=1002
Dec 16 21:33:36 ldap3-dev slapd[7782]: connection_read(15): checking for input on id=1002
Dec 16 21:33:36 ldap3-dev slapd[7782]: op tag 0x60, time 1418765616
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=0 do_bind
Dec 16 21:33:36 ldap3-dev slapd[7782]: >>> dnPrettyNormal: <cn=admin,dc=example,dc=org>
Dec 16 21:33:36 ldap3-dev slapd[7782]: <<< dnPrettyNormal: <cn=admin,dc=example,dc=org>, <cn=admin,dc=example,dc=org>
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=0 BIND dn="cn=admin,dc=example,dc=org" method=128
Dec 16 21:33:36 ldap3-dev slapd[7782]: do_bind: version=3 dn="cn=admin,dc=example,dc=org" method=128
Dec 16 21:33:36 ldap3-dev slapd[7782]: ==> hdb_bind: dn: cn=admin,dc=example,dc=org
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=0 BIND dn="cn=admin,dc=example,dc=org" mech=SIMPLE ssf=0
Dec 16 21:33:36 ldap3-dev slapd[7782]: do_bind: v3 bind: "cn=admin,dc=example,dc=org" to "cn=admin,dc=example,dc=org"
Dec 16 21:33:36 ldap3-dev slapd[7782]: send_ldap_result: conn=1002 op=0 p=3
Dec 16 21:33:36 ldap3-dev slapd[7782]: send_ldap_result: err=0 matched="" text=""
Dec 16 21:33:36 ldap3-dev slapd[7782]: send_ldap_response: msgid=1 tag=97 err=0
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=0 RESULT tag=97 err=0 text=
Dec 16 21:33:36 ldap3-dev slapd[7782]: connection_get(15)
Dec 16 21:33:36 ldap3-dev slapd[7782]: connection_get(15): got connid=1002
Dec 16 21:33:36 ldap3-dev slapd[7782]: connection_read(15): checking for input on id=1002
Dec 16 21:33:36 ldap3-dev slapd[7782]: op tag 0x66, time 1418765616
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=1 do_modify
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=1 do_modify: dn (uid=kebrahimpour,ou=people,dc=example,dc=org)
Dec 16 21:33:36 ldap3-dev slapd[7782]: >>> dnPrettyNormal: <uid=kebrahimpour,ou=people,dc=example,dc=org>
Dec 16 21:33:36 ldap3-dev slapd[7782]: <<< dnPrettyNormal: <uid=kebrahimpour,ou=people,dc=example,dc=org>, <uid=kebrahimpour,ou=people,dc=example,dc=org>
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=1 modifications:
Dec 16 21:33:36 ldap3-dev slapd[7782]: replace: gecos
Dec 16 21:33:36 ldap3-dev slapd[7782]: one value, length 7
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=1 MOD dn="uid=kebrahimpour,ou=people,dc=example,dc=org"
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=1 MOD attr=gecos
Dec 16 21:33:36 ldap3-dev slapd[7782]: bdb_dn2entry("uid=kebrahimpour,ou=people,dc=example,dc=org")
Dec 16 21:33:36 ldap3-dev slapd[7782]: => hdb_dn2id("ou=people,dc=example,dc=org")
Dec 16 21:33:36 ldap3-dev slapd[7782]: <= hdb_dn2id: got id=0x5
Dec 16 21:33:36 ldap3-dev slapd[7782]: => hdb_dn2id("uid=kebrahimpour,ou=people,dc=example,dc=org")
Dec 16 21:33:36 ldap3-dev slapd[7782]: <= hdb_dn2id: got id=0x13
Dec 16 21:33:36 ldap3-dev slapd[7782]: entry_decode: ""
Dec 16 21:33:36 ldap3-dev slapd[7782]: <= entry_decode()
Dec 16 21:33:36 ldap3-dev slapd[7782]: send_ldap_result: conn=1002 op=1 p=3
Dec 16 21:33:36 ldap3-dev slapd[7782]: send_ldap_result: err=10 matched="" text=""
Dec 16 21:33:36 ldap3-dev slapd[7782]: send_ldap_result: referral="ldap://ldap1-dev.example.com/uid=kebrahimpour,ou=people,dc=example,dc=org"
Dec 16 21:33:36 ldap3-dev slapd[7782]: >>> dnPrettyNormal: <uid=kebrahimpour,ou=people,dc=example,dc=org>
Dec 16 21:33:36 ldap3-dev slapd[7782]: <<< dnPrettyNormal: <uid=kebrahimpour,ou=people,dc=example,dc=org>, <uid=kebrahimpour,ou=people,dc=example,dc=org>
Dec 16 21:33:36 ldap3-dev slapd[7782]: conn=1002 op=1 ldap_chain_op: ref="ldap://ldap1-dev.example.com/uid=kebrahimpour,ou=people,dc=example,dc=org" -> "ldap://ldap1-dev.example.com"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment