[MXS-4506] Add passthrough authentication support for Xpand LDAP Created: 2023-02-13  Updated: 2023-09-13  Resolved: 2023-08-17

Status: Closed
Project: MariaDB MaxScale
Component/s: mariadbclient
Affects Version/s: None
Fix Version/s: 23.08.0

Type: New Feature Priority: Major
Reporter: Patrick Bossman (Inactive) Assignee: Esa Korhonen
Resolution: Fixed Votes: 0
Labels: None

Issue Links:
Relates
Sprint: MXS-SPRINT-181, MXS-SPRINT-182, MXS-SPRINT-186, MXS-SPRINT-187, MXS-SPRINT-188

 Description   

Xpand is adding authentication to LDAP directly within Xpand. The users are only stored in LDAP. Xpand requires the client cleartext password to authenticate against LDAP.

Add support for MaxScale to handle unknown user by connecting immediately through Xpand, without assuming the authentication will succeed. (Currently, MaxScale can support unknown user, but it assumes the connection will be successful and returns success to the client immediately. Connection then get deferred to when first SQL is executed).

This is needed for support for LDAP in Xpand which is slotted for Transylvania release, end of 2Q2023.



 Comments   
Comment by Daman Saini (Inactive) [ 2023-09-13 ]

In final build of 23.08.0 , Listener parameter for LDAP passthrough is

authenticator_options=clear_pw_passthrough=true

Generated at Thu Feb 08 04:29:08 UTC 2024 using Jira 8.20.16#820016-sha1:9d11dbea5f4be3d4cc21f03a88dd11d8c8687422.