Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WIP: VAULT-31525 removing force lowercase on user reads #28606

Closed
wants to merge 7 commits into from

Conversation

JMGoldsmith
Copy link
Collaborator

@JMGoldsmith JMGoldsmith commented Oct 7, 2024

Description

What does this PR do?

This PR will change the behavior of the RADIUS authentication plugin for Vault. It will now allow for users with capital letters in their usernames to be used within Vault. Previous behavior would return an all lower case user, which would be rejected by the RADIUS server if it was expecting mixed case or all caps.

This was changed due to user reports of issues with capitalization.

Existing usernames that were all lower case will not be affected, but if you use mixed case or all capitals, you will now be able to properly authenticate.

TODO only if you're a HashiCorp employee

  • [x ] Backport Labels: If this PR is in the ENT repo and needs to be backported, backport
    to N, N-1, and N-2, using the backport/ent/x.x.x+ent labels. If this PR is in the CE repo, you should only backport to N, using the backport/x.x.x label, not the enterprise labels.
    • If this fixes a critical security vulnerability or severity 1 bug, it will also need to be backported to the current LTS versions of Vault. To ensure this, use all available enterprise labels.
  • ENT Breakage: If this PR either 1) removes a public function OR 2) changes the signature
    of a public function, even if that change is in a CE file, double check that
    applying the patch for this PR to the ENT repo and running tests doesn't
    break any tests. Sometimes ENT only tests rely on public functions in CE
    files.
  • [x ] Jira: If this change has an associated Jira, it's referenced either
    in the PR description, commit message, or branch name.
  • RFC: If this change has an associated RFC, please link it in the description.
  • ENT PR: If this change has an associated ENT PR, please link it in the
    description. Also, make sure the changelog is in this PR, not in your ENT PR.

Copy link

hashicorp-cla-app bot commented Oct 7, 2024

CLA assistant check

Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement

Learn more about why HashiCorp requires a CLA and what the CLA includes


1 out of 2 committers have signed the CLA.

  • JMGoldsmith
  • John Goldsmith

John Goldsmith seems not to be a GitHub user.
You need a GitHub account to be able to sign the CLA.
If you have already a GitHub account, please add the email address used for this commit to your account.

Have you signed the CLA already but the status is still pending? Recheck it.

@github-actions github-actions bot added the hashicorp-contributed-pr If the PR is HashiCorp (i.e. not-community) contributed label Oct 7, 2024
Copy link

github-actions bot commented Oct 7, 2024

CI Results:
All Go tests succeeded! ✅

Copy link

github-actions bot commented Oct 7, 2024

Build Results:
Build failed for these jobs: artifacts:failure. Please refer to this workflow to learn more: https://github.com/hashicorp/vault/actions/runs/11798595546

@JMGoldsmith JMGoldsmith requested a review from a team October 7, 2024 15:13
@JMGoldsmith JMGoldsmith changed the title WIP: VAULT-31525 removing force lowercase on user reads VAULT-31525 removing force lowercase on user reads Oct 28, 2024
@JMGoldsmith JMGoldsmith added the backport/ent/1.17.x+ent Changes are backported to 1.17.x+ent label Oct 28, 2024
@JMGoldsmith JMGoldsmith changed the title VAULT-31525 removing force lowercase on user reads WIP: VAULT-31525 removing force lowercase on user reads Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport/ent/1.16.x+ent Changes are backported to 1.16.x+ent backport/ent/1.17.x+ent Changes are backported to 1.17.x+ent hashicorp-contributed-pr If the PR is HashiCorp (i.e. not-community) contributed pr/no-milestone
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants