LDAP Authentication: Malformed LDAP Filter Syntax, Authorization Works Only for Root Admin
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- java
- Domain
- authentication, backend
Research direction
Start by reproducing LDAP user import and a non-Root Admin login on CloudStack 4.22.1.0, then inspect the management server logs and LDAP search request shown in the issue. Done means the generated LDAP filter is syntactically valid, LDAP import succeeds, and users without the Root Admin role can load the UI.
Written by the indexing model from the issue text.
Description
problem
Issue Description
After upgrading CloudStack from version 4.21.0.0 to 4.22.1.0, LDAP user authentication stopped working for all roles except Root Admin.
Symptoms
- Root Admin — authentication succeeds, UI works correctly
- Non-Root Admin users — authentication appears to succeed, but after login:
- System cannot load any components in the zone
- UI shows "infinite page loading" that ends in timeout
Behavior on Fresh Installation
When testing on a new CloudStack 4.22.1.0 instance with LDAP user import, logs show an error — malformed LDAP filter syntax (extra opening parenthesis ( at the end):
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
Comparison with Working Version (Root Admin)
On the version where Root Admin works correctly, the filter looks correct:
{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
versions
Environment
| Parameter | Value |
|---|---|
| Product | Apache CloudStack |
| Version (before upgrade) | 4.21.0.0 |
| Version (after upgrade) | 4.22.1.0 |
| Hypervision | KVM |
The steps to reproduce the bug
Steps to Reproduce
Scenario 1: Upgrade from 4.21.0.0 → 4.22.1.0
- Install CloudStack 4.21.0.0 with LDAP authentication configured
- Upgrade to version 4.22.1.0
- Attempt to login as a user without Root Admin role
- Observed result:
- Login appears successful
- UI does not load components (infinite loading → timeout)
Scenario 2: Fresh Installation 4.22.1.0
- Deploy new CloudStack 4.22.1.0 instance
- Configure LDAP authentication (goauthentik or similar server)
- Import users from LDAP
- Check CloudStack Management Server logs
- Observed result:
- LDAP query with malformed filter (extra
(at the end)
- LDAP query with malformed filter (extra
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
Comparison with Working Version (Root Admin)
On the version where Root Admin works correctly, the filter looks correct:
{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
What to do about it?
Expected Behavior
- LDAP filter should be syntactically correct
- Users of all roles (not only Root Admin) should successfully authenticate and access the UI
- Filter should match the format:
(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*))
Actual Behavior
- LDAP filter contains syntax error:
(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)( - Non-Root Admin users cannot work in UI after authentication
- On fresh installation, LDAP user import fails due to invalid filter
Questions
- How to fix permissions in the "upgraded" CloudStack version where only Root Admin can authenticate without issues?
- How to fix the issue in fresh installation with the LDAP query error (malformed filter syntax)?
- Dominant language
- Java
- Stars
- 3.1k
- Forks
- 1.4k
- Avg merge
- 6d 20h
- Merged PRs (30d)
- 27
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/cloudstack
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 90/100
apache/cloudstack#14222 ·
-
bug component:kubernetes
Difficulty 1/5 Under an hour Newbie friendliness 88/100
apache/cloudstack#14180 ·
-
bug component:projects component:UI
Difficulty 1/5 Under an hour Newbie friendliness 88/100
apache/cloudstack#14070 · 5 comments ·
-
component:backup
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
apache/cloudstack#14013 ·
-
KVM agent fails to connect to Ceph RBD storage pool after upgrading Ceph client to Tentacle 20.2.4 Openbug component:ceph
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
apache/cloudstack#13989 · 3 comments ·
All issues in apache/cloudstack
Similar issues
-
area/plugin
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
kestra-io/plugin-kestra#190 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
google-ai-edge/LiteRT-LM#3739 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
integra-team-red/meet-map#249 ·
-
[Studio][Bug] Cancelled create-user dialog keeps the password and admin switch for the next attempt Open
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
apache/rocketmq-dashboard#5064 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
wso2/dpdp-accelerator#287 ·