You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
hiera-ldap monkey-patches Net::LDAP to disable SSL certificate validation for every connection made, even if done by other code in the same instance. This allows MitM attacks on every connection made. This problem is categorized as CWE-295.
The text was updated successfully, but these errors were encountered:
As I recall we had to do this because puppet itself was monkey patching Net::LDAP so we had to 'unmonkey' patch it. I also think there was something mumble mumble ruby versions. @petems you want to try using the plugin without the ssl patching and see how it goes today? or @nightfly19 ? I no longer use this software so I'm not the best candidate for driving its development.
I'll have a quick go, I'm not able to access a real LDAP instance easily (was at customer site at the time) but I think I should be able to test this with ladle.
hiera-ldap monkey-patches Net::LDAP to disable SSL certificate validation for every connection made, even if done by other code in the same instance. This allows MitM attacks on every connection made. This problem is categorized as CWE-295.
The text was updated successfully, but these errors were encountered: