View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0005846 | SOGo | GUI | public | 2023-08-22 16:19 | 2023-11-27 09:01 |
Reporter | MrT2020 | Assigned To | |||
Priority | normal | Severity | feature | Reproducibility | always |
Status | new | Resolution | open | ||
Platform | Linux | OS | Debian | OS Version | 11 and 12 |
Product Version | 5.8.4 | ||||
Summary | 0005846: passwordRecovery via Email with OpenLDAP server 2.5 fails because sending old new to Ldap | ||||
Description | sogo 5.8.4.20230821-1 is not an issue with ACL on slapd, because access is granted: => slap_access_allowed: auth access granted by manage(=mwrscxd) sogo triggers PASSMOD on slapd with old new -> unwilling to verify old password (how old password is fetch because user does input it - in passwordRecovery via gui only new is queried, of course ;-) ) PASSMOD id="" new -> only submitting the new password would work Any chance to get a kind of ldap configuration parameter enforcing ldap password change with new password only (for open ldap) ? br | ||||
Tags | No tags attached. | ||||
same situation with 5.9.0 sogo.conf important sectionbindDN = "uid=sogo,dc=internal";
|
|
Thank you for reporting this ! Sebastien |
|