I have a confluence server that authenticates against an OpenLDAP server. This is working fine, it obeys the groups, obeys the users, lets users change their password, etc.
This is also where the problem comes in, when changing passwords it doesn't seem to be behaving the same way a ldappasswd command would, it is allowing users to override the password policy for instance (length, complexity). Those are being enforced when I run ldappasswd or passwd on a general linux machine.
I assume this is happening because the query is being executed as the bind user, which has access to change the userPassword field without going through the pwpolicy module.
Is there a way to have Confluence bind as the user vs the binddn for password changes? That should fix that problem.
Two vulnerabilities have been published for Confluence Server and Data Center recently: March 20, 2019 CVE-2019-3395 / CVE-2019-3396 April 17, 2019 CVE-2019-3398 The goal of this article is...
Connect with like-minded Atlassian users at free events near you!Find a group
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no AUG chapters near you at the moment.Start an AUG
You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs