Return-Path: Delivered-To: apmail-directory-dev-archive@www.apache.org Received: (qmail 96529 invoked from network); 16 Mar 2007 10:51:15 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 16 Mar 2007 10:51:14 -0000 Received: (qmail 57123 invoked by uid 500); 16 Mar 2007 10:51:22 -0000 Delivered-To: apmail-directory-dev-archive@directory.apache.org Received: (qmail 57078 invoked by uid 500); 16 Mar 2007 10:51:22 -0000 Mailing-List: contact dev-help@directory.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Apache Directory Developers List" Delivered-To: mailing list dev@directory.apache.org Received: (qmail 57067 invoked by uid 99); 16 Mar 2007 10:51:22 -0000 Received: from herse.apache.org (HELO herse.apache.org) (140.211.11.133) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 16 Mar 2007 03:51:22 -0700 X-ASF-Spam-Status: No, hits=2.0 required=10.0 tests=HTML_MESSAGE,SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (herse.apache.org: domain of elecharny@gmail.com designates 64.233.182.184 as permitted sender) Received: from [64.233.182.184] (HELO nf-out-0910.google.com) (64.233.182.184) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 16 Mar 2007 03:51:11 -0700 Received: by nf-out-0910.google.com with SMTP id o25so199833nfa for ; Fri, 16 Mar 2007 03:50:49 -0700 (PDT) DKIM-Signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:references; b=U2w+FV9Ww05JLL7j3Cy6raLR056+kJRz7SRNCyOG+idgMgyIwsP7vKi0+b4bL/1SQN6udykNnniFuJe85O2ESXlYasctaLR+Y62sueSSu+nVVm7tM8mmf+W+osv7q8KcwxoveGEeW/WzESXbidO8YQ03Q/EMq+C3hfVvIzp54gs= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:references; b=PBcJzSbEzmcaDiZIAZUQvLyPFytwYDmQoXvvq1oLhgp5n2qd6B7uaHSJ89koUyISdV8a5Yke1BMzSMY8gVYhvqTOZXt62UGvOlj1CuBdqSP7goGJsEoiXgRj3DtaLAi3hMzwuxpEZQQzAFQJnSINbLe9cOGrvJwbich+txGKiaw= Received: by 10.78.181.13 with SMTP id d13mr895312huf.1174042249692; Fri, 16 Mar 2007 03:50:49 -0700 (PDT) Received: by 10.78.23.3 with HTTP; Fri, 16 Mar 2007 03:50:49 -0700 (PDT) Message-ID: Date: Fri, 16 Mar 2007 11:50:49 +0100 From: "Emmanuel Lecharny" Reply-To: elecharny@iktek.com To: "Flavio Minori" Subject: Re: R: [ApacheDS] Password refresh Cc: "Apache Directory Developers List" In-Reply-To: <000e01c767b6$fa9e5de0$2a00a8c0@topcs.it> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_83628_18278318.1174042249583" References: <000e01c767b6$fa9e5de0$2a00a8c0@topcs.it> X-Virus-Checked: Checked by ClamAV on apache.org ------=_Part_83628_18278318.1174042249583 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: quoted-printable Content-Disposition: inline On 3/16/07, Flavio Minori wrote: > > Hello Emmanuel, > thanks for the reply. > > I am going to check the links you gave me. > > I use JXplorer to browse the APACHE DS and I noticed something that I am > not > able to explain myself, those are the steps: > > - I connect with my user, then I remove the userPassword attribute and > submit it (so the userPassword attribute exists with a blank > value). > - I change the password and disconnect. > - Now, I connect again with the new password and it works! > > Can u tell me why seems that JXplorer can remove the principal/credential= s > from the authenticationCache without a LDAPServer restart? Ooops, I think we have fixed the issue in the 1.0.1 version : https://issues.apache.org/jira/browse/DIRSERVER-782 This is why it now works for you with JXplorer. In your code, you have to know that the credentials are kept alive until th= e user disconnect. It may be improved. Might it be that it is a simple error on my code and not related to any bug= ? Don't know at this point ... If you can build a very simple test which expose your problem, we can try t= o find a fix for it. What about filling an issue on JIRA with this piece of code so that we try to add it to the 1.0.2 release ? (we are trying to release this version ver= y soon, so it's good timing ) Emmanuel. PS : FYI, we have LdapStudio which is also a ldapBrowser you can try : http://directory.apache.org/ldapstudio/. It's not yet an official release, but the Ldap browser is pretty much ok, I think. --=20 Cordialement, Emmanuel L=E9charny www.iktek.com ------=_Part_83628_18278318.1174042249583 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline

On 3/16/07, Flavio Minori <fla= vio.minori@topcs.it> wrote:
Hello Emmanuel,
thanks for the reply.

I am going to check the lin= ks you gave me.

I use JXplorer to browse the APACHE DS and I noticed= something that I am not
able to explain myself, those are the steps:

- I connect with my user, then I remove the userPassword attribute = and
submit it (so         &= nbsp;  the userPassword attribute exists with a blank
value).<= br>- I change the password and disconnect.
- Now, I connect again with t= he new password and it works!

Can u tell me why seems that JXplorer can remove the principal/cred= entials
from the authenticationCache without a LDAPServer restart?

Ooops, I think we have fixed the issue in the 1.0.1 version= :
https:/= /issues.apache.org/jira/browse/DIRSERVER-782

This is why it now = works for you with JXplorer.

In your code, you have to know that the= credentials are kept alive until the user disconnect. It may be improved.


Might it be that it is a simple error on my code and not related to any bu= g?

Don't know at this point ...
If you can= build a very simple test which expose your problem, we can try to find a f= ix for it.

What about filling an issue on JIRA with this piece of co= de so that we try to add it to the=20 1.0.2 release ? (we are trying to release this version very soon, so it'= ;s good timing )

Emmanuel.

PS : FYI, we have LdapStudio which= is also a ldapBrowser you can try : http://directory.apache.org/ldapstudio/. It's not yet an official r= elease, but the Ldap browser is pretty much ok, I think.

-- Cordialement,
Emmanuel L=E9charny
www.iktek.com ------=_Part_83628_18278318.1174042249583--