Bug 240 - [vAPV] Need to integrate Admin Account with ADFS and LDAP server for AAA || State Bank of India

Review Request #116 — Created Jan. 16, 2024 and submitted

kdutta
APV10
rel_apv_10_4_0_112_sbi
240
pradeep, prajesh, tanya

Bug 240 - [vAPV] Need to integrate Admin Account with ADFS and LDAP server for AAA || State Bank of India

Basic UT done

login as: kdutta@arraylab.in
kdutta@arraylab.in@192.168.11.138's password:
Last login: Thu Jan 18 17:48:37 2024 from 192.168.11.98
ArrayOS Rel.APV.10.4.0.112.6 - untagged unofficial build by uid=0(root) gid=0(root) groups=0(root) on DevAnsuk: on Thu Jan 18 06:01:33 2024
Copyright (c) 2000-2024 Array Networks Inc. All rights reserved.

Type "?" for available commands

!!Reminder!! Please log on to the WebUI to register this system.

AN>

Thu Jan 18 17:38:38 2024 Generated LDAP handle for uri ldap://192.168.102.100:389.

Thu Jan 18 17:38:38 2024 LDAP connection successful.

Description From Last Updated

Nitpick: remove extra whitespaces at the end.

prajeshprajesh

where do these logs go?

prajeshprajesh

[root@AN test]# tail -f /var/crash/exau.log Tue Jan 23 15:22:23 2024 ldap_simple_bind_s: Invalid credentials

kduttakdutta

We need to add audit log for stating login failure.

prajeshprajesh

i am using the same existing log used for external authentication.

kduttakdutta

Need a audit log for successful user login. - Add username to the log message in both cases.

prajeshprajesh

return value of ldap response type?

pradeeppradeep

we can move "ldap_unbind_ext_s" to "else" clause. And for both "if and else" we can just have one "return"

pradeeppradeep
prajesh
  1. 
      
  2. Nitpick: remove extra whitespaces at the end.

  3. 
      
kdutta
kdutta
prajesh
prajesh
  1. 
      
  2. We need to add audit log for stating login failure.

  3. Need a audit log for successful user login. - Add username to the log message in both cases.

  4. 
      
kdutta
kdutta
  1. 
      
  2. [root@AN test]# tail -f /var/crash/exau.log

    Tue Jan 23 15:22:23 2024 ldap_simple_bind_s: Invalid credentials

  3. 
      
kdutta
  1. 
      
  2. i am using the same existing log used for external authentication.

  3. 
      
kdutta
kdutta
prajesh
  1. Ship It!
  2. 
      
pradeep
  1. 
      
  2. return value of ldap response type?

  3. we can move "ldap_unbind_ext_s" to "else" clause. And for both "if and else" we can just have one "return"

    1. This is fine, like after operation is over we need to clear the ldap connection kind of.

  4. 
      
kdutta
kdutta
pradeep
  1. ship it

  2. 
      
kdutta
Review request changed

Status: Closed (submitted)

tanya
  1. Ship It!
  2. 
      
Loading...