LDAP Authentication: Malformed LDAP Filter Syntax, Authorization Works Only for Root Admin
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 45/100
- Tipo de issue
- Bug
- Clareza
- Razoavelmente clara
- Status de atividade
- Ativa
- Stack de tecnologia
- java
- Domínio
- authentication, backend
Direção de pesquisa
Comece reproduzindo a importação de usuários LDAP e um login de um usuário que não seja Root Admin no CloudStack 4.22.1.0; em seguida, inspecione os logs do servidor de gerenciamento e a solicitação de pesquisa LDAP mostrada na issue. Está concluído quando o filtro LDAP gerado for sintaticamente válido, a importação LDAP for bem-sucedida e os usuários sem a função Root Admin conseguirem carregar a UI.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
problem
Issue Description
After upgrading CloudStack from version 4.21.0.0 to 4.22.1.0, LDAP user authentication stopped working for all roles except Root Admin.
Symptoms
- Root Admin — authentication succeeds, UI works correctly
- Non-Root Admin users — authentication appears to succeed, but after login:
- System cannot load any components in the zone
- UI shows "infinite page loading" that ends in timeout
Behavior on Fresh Installation
When testing on a new CloudStack 4.22.1.0 instance with LDAP user import, logs show an error — malformed LDAP filter syntax (extra opening parenthesis ( at the end):
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
Comparison with Working Version (Root Admin)
On the version where Root Admin works correctly, the filter looks correct:
{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
versions
Environment
| Parameter | Value |
|---|---|
| Product | Apache CloudStack |
| Version (before upgrade) | 4.21.0.0 |
| Version (after upgrade) | 4.22.1.0 |
| Hypervision | KVM |
The steps to reproduce the bug
Steps to Reproduce
Scenario 1: Upgrade from 4.21.0.0 → 4.22.1.0
- Install CloudStack 4.21.0.0 with LDAP authentication configured
- Upgrade to version 4.22.1.0
- Attempt to login as a user without Root Admin role
- Observed result:
- Login appears successful
- UI does not load components (infinite loading → timeout)
Scenario 2: Fresh Installation 4.22.1.0
- Deploy new CloudStack 4.22.1.0 instance
- Configure LDAP authentication (goauthentik or similar server)
- Import users from LDAP
- Check CloudStack Management Server logs
- Observed result:
- LDAP query with malformed filter (extra
(at the end)
- LDAP query with malformed filter (extra
{"attributes":["uid","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)(
Comparison with Working Version (Root Admin)
On the version where Root Admin works correctly, the filter looks correct:
{"attributes":["cn","mail","givenname","sn","cn","userAccountControl","memberof"],"baseDN":"DC=ldap,DC=goauthentik,DC=io","bindDN":"cn=ldapservice,ou=users,dc=ldap,dc=goauthentik,dc=io","client":"X.X.X.X.","event":"Search request","filter":"(&(&(objectCategory=person)(objectClass=inetOrgPerson))(cn=*))","level":"info","requestId":"c411e2c7-0468-46af-9120-b7d1fc652f36","scope":"Whole Subtree","timestamp":"2026-08-26T11:13:44Z","took-ms":15}
What to do about it?
Expected Behavior
- LDAP filter should be syntactically correct
- Users of all roles (not only Root Admin) should successfully authenticate and access the UI
- Filter should match the format:
(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*))
Actual Behavior
- LDAP filter contains syntax error:
(&(&(objectCategory=person)(objectClass=inetOrgPerson))(uid=*)( - Non-Root Admin users cannot work in UI after authentication
- On fresh installation, LDAP user import fails due to invalid filter
Questions
- How to fix permissions in the "upgraded" CloudStack version where only Root Admin can authenticate without issues?
- How to fix the issue in fresh installation with the LDAP query error (malformed filter syntax)?
- Linguagem predominante
- Java
- Estrelas
- 3.1k
- Forks
- 1.4k
- Merge médio
- 6d 20h
- PRs com merge (30d)
- 27
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de apache/cloudstack
-
bug
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
apache/cloudstack#14222 ·
-
create-kubernetes-binaries-iso.sh builds the ISO without setting a volume ID on EL8 based os's Abertabug component:kubernetes
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
apache/cloudstack#14180 ·
-
bug component:projects component:UI
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
apache/cloudstack#14070 · 5 comentários ·
-
component:backup
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
apache/cloudstack#14013 ·
-
KVM agent fails to connect to Ceph RBD storage pool after upgrading Ceph client to Tentacle 20.2.4 Abertabug component:ceph
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
apache/cloudstack#13989 · 3 comentários ·
Todas as issues de apache/cloudstack
Issues semelhantes
-
executions.Query — startDate and timeRange filters are sent with inverted comparison operators Abertaarea/plugin
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
kestra-io/plugin-kestra#190 ·
-
litertlm-android AAR ships no consumer ProGuard rules → "mid == null" SIGABRT in minified apps Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
google-ai-edge/LiteRT-LM#3739 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
integra-team-red/meet-map#249 ·
-
[Studio][Bug] Cancelled create-user dialog keeps the password and admin switch for the next attempt Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
apache/rocketmq-dashboard#5064 ·
-
Consent portal: creating a duplicate Purpose shows a generic error instead of "already exists" Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
wso2/dpdp-accelerator#287 ·