Skip to content

Commit

Permalink
Fix scheme for DialURL ldap connection (#3677)
Browse files Browse the repository at this point in the history
* Use scheme without :// suffix
* Make test ldap server listen on custom ports to avoid stepping into go-ldap defaults

Signed-off-by: m.nabokikh <[email protected]>
  • Loading branch information
nabokihms committed Aug 7, 2024
1 parent 257a821 commit 54fb570
Show file tree
Hide file tree
Showing 3 changed files with 7 additions and 7 deletions.
4 changes: 2 additions & 2 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -121,8 +121,8 @@ jobs:
DEX_ETCD_ENDPOINTS: http://localhost:${{ job.services.etcd.ports[2379] }}

DEX_LDAP_HOST: localhost
DEX_LDAP_PORT: 389
DEX_LDAP_TLS_PORT: 636
DEX_LDAP_PORT: 3890
DEX_LDAP_TLS_PORT: 6360

DEX_KEYSTONE_URL: http://localhost:${{ job.services.keystone.ports[5000] }}
DEX_KEYSTONE_ADMIN_URL: http://localhost:${{ job.services.keystone.ports[35357] }}
Expand Down
6 changes: 3 additions & 3 deletions connector/ldap/ldap.go
Original file line number Diff line number Diff line change
Expand Up @@ -322,10 +322,10 @@ func (c *ldapConnector) do(_ context.Context, f func(c *ldap.Conn) error) error

switch {
case c.InsecureNoSSL:
u := url.URL{Scheme: "ldap://", Host: c.Host}
u := url.URL{Scheme: "ldap", Host: c.Host}
conn, err = ldap.DialURL(u.String())
case c.StartTLS:
u := url.URL{Scheme: "ldap://", Host: c.Host}
u := url.URL{Scheme: "ldap", Host: c.Host}
conn, err = ldap.DialURL(u.String())
if err != nil {
return fmt.Errorf("failed to connect: %v", err)
Expand All @@ -334,7 +334,7 @@ func (c *ldapConnector) do(_ context.Context, f func(c *ldap.Conn) error) error
return fmt.Errorf("start TLS failed: %v", err)
}
default:
u := url.URL{Scheme: "ldaps://", Host: c.Host}
u := url.URL{Scheme: "ldaps", Host: c.Host}
conn, err = ldap.DialURL(u.String(), ldap.DialWithTLSConfig(c.tlsConfig))
}
if err != nil {
Expand Down
4 changes: 2 additions & 2 deletions docker-compose.test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,8 @@ services:
LDAP_TLS: "true"
LDAP_TLS_VERIFY_CLIENT: try
ports:
- 389:389
- 636:636
- 3890:389
- 6360:636
volumes:
- ./connector/ldap/testdata/certs:/container/service/slapd/assets/certs
- ./connector/ldap/testdata/schema.ldif:/container/service/slapd/assets/config/bootstrap/ldif/99-schema.ldif

0 comments on commit 54fb570

Please sign in to comment.