users@glassfish.java.net

Glassfish does not perform a nested group lookup in LDAP Realm

From: <forums_at_java.net>
Date: Mon, 27 Aug 2012 04:56:15 -0500 (CDT)

Hi, I have a Glassfish 3.1.2 installation and face the following problem.
Having a LDAP Realm configured, glassfish does only support direct membership
matching in LDAP when trying to check for authorization. If a application
role contains other LDAP groups, these groups are not checked for having
logged in user. This issue is also reported to this post
http://www.java.net/forum/topic/glassfish/glassfish/ldap-nested-groups Is
there any work around for this issue. In complex user managment systems to
force only direct matching is very restrictive. Any comment will be helpful.

--
[Message sent by forum member 'istavrakis']
View Post: http://forums.java.net/node/889585