From 31f89121fecca5a761b05cc3a26d4f237e90b484 Mon Sep 17 00:00:00 2001 From: Robert Scheck Date: Mon, 25 Jan 2021 23:42:22 +0100 Subject: [PATCH] Reject by default LDAP connections not authorized via CA trust store See also: https://github.com/wekan/wekan/issues/3482 --- packages/wekan-ldap/server/ldap.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/wekan-ldap/server/ldap.js b/packages/wekan-ldap/server/ldap.js index f2d9a7b72..5db8f2cb8 100644 --- a/packages/wekan-ldap/server/ldap.js +++ b/packages/wekan-ldap/server/ldap.js @@ -19,7 +19,7 @@ export default class LDAP { idle_timeout : this.constructor.settings_get('LDAP_IDLE_TIMEOUT'), encryption : this.constructor.settings_get('LDAP_ENCRYPTION'), ca_cert : this.constructor.settings_get('LDAP_CA_CERT'), - reject_unauthorized : this.constructor.settings_get('LDAP_REJECT_UNAUTHORIZED') || false, + reject_unauthorized : this.constructor.settings_get('LDAP_REJECT_UNAUTHORIZED') || true, Authentication : this.constructor.settings_get('LDAP_AUTHENTIFICATION'), Authentication_UserDN : this.constructor.settings_get('LDAP_AUTHENTIFICATION_USERDN'), Authentication_Password : this.constructor.settings_get('LDAP_AUTHENTIFICATION_PASSWORD'),