FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Change LoadDomainInfo to honor requested LDAP port by JasonDebug · Pull Request #89787 · dotnet/runtime · GitHub

Repository navigation

Change LoadDomainInfo to honor requested LDAP port - #89787

Merged
steveharter merged 2 commits into
dotnet:mainfrom
JasonDebug:bugfix/LoadDomainInfo-ignores-portnumber
Sep 13, 2023
Merged

steveharter merged 2 commits into
dotnet:mainfrom
JasonDebug:bugfix/LoadDomainInfo-ignores-portnumber

Conversation

JasonDebug commented Aug 1, 2023 •
edited
Loading

Copy link
Copy Markdown
Contributor

Fixes #65894

LoadDomainInfo builds an LDAP Uri that ignores the requested port. If LDAPS/636 is requested, traffic still goes to 389 for this request. For environments where port 389 is blocked, this causes calls such as GroupPrincipal.GetMembers() to fail when the group is Domain Local or Universal. We do not seem to call LoadDomainInfo for Global groups.

This PR will use the specified port for the call, 389 if no port is specified, or 636 if LDAPS is specified.

dotnet#65894

LoadDomainInfo builds an LDAP Uri that ignores the requested port.  If LDAPS/636 is requested, traffic still goes to 389 for this request.
ghost added area-System.DirectoryServices community-contribution Indicates that the PR has been added by a community member labels Aug 1, 2023

ghost commented Aug 1, 2023

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-directoryservices, @jay98014
See info in area-owners.md if you want to be subscribed.

Issue Details

#65894

LoadDomainInfo builds an LDAP Uri that ignores the requested port. If LDAPS/636 is requested, traffic still goes to 389 for this request. For environments where port 389 is blocked, this causes calls such as GroupPrincipal.GetMembers() to fail.

This PR will use the specified port for the call, 389 if no port is specified, or 636 if LDAPS is specified.

Author: JasonDebug
Assignees: -
Labels:

area-System.DirectoryServices, community-contribution

Milestone: -

Copy link
Copy Markdown
Contributor

PTAL @jay98014 and @kumarravi

ericstj assigned jay98014 and unassigned jay98014 Sep 5, 2023
ericstj requested review from kumarravik78c and removed request for kumarravi September 6, 2023 16:17

kumarravik78c left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

I have validated this PR on my local set up and made sure this fixes the issue, hence approving.

steveharter self-requested a review September 13, 2023 20:08

steveharter left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Approving based on approval from @kumarravik78c

steveharter merged commit a4b8dc2 into dotnet:main Sep 13, 2023

// Pull the requested port number
Uri ldapUri = new Uri(this.ctxBase.Path);
int port = ldapUri.Port != -1 ? ldapUri.Port : (ldapUri.Scheme.ToUpperInvariant() == "LDAPS" ? 636 : 389);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

String.Equals(..., StringComparison.OrdinalIgnoreCase) avoids an unnecessary allocation.

ghost locked as resolved and limited conversation to collaborators Oct 14, 2023
JasonDebug deleted the bugfix/LoadDomainInfo-ignores-portnumber branch November 20, 2023 16:31
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-System.DirectoryServices community-contribution Indicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Ldap GetMembers working over 389 port

5 participants


Back | FazBrowse Home | New Git URL