From 95113b9c8473a6d33010e27910771299c25d35e0 Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Thu, 18 Aug 2016 16:02:20 +0100 Subject: [PATCH] Skip whoami check for LDAP servers not supporting it Fix #2805. --- lib/galaxy/auth/providers/ldap_ad.py | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/lib/galaxy/auth/providers/ldap_ad.py b/lib/galaxy/auth/providers/ldap_ad.py index 095bf0179ac..93650ee394e 100644 --- a/lib/galaxy/auth/providers/ldap_ad.py +++ b/lib/galaxy/auth/providers/ldap_ad.py @@ -162,12 +162,20 @@ class LDAP(AuthProvider): l = ldap.initialize(_get_subs(options, 'server', params)) l.protocol_version = 3 + bind_password = _get_subs(options, 'bind-password', params) + if not bind_password: + raise RuntimeError('LDAP authenticate: empty password') l.simple_bind_s(_get_subs( - options, 'bind-user', params), _get_subs(options, 'bind-password', params)) - whoami = l.whoami_s() - log.debug("LDAP authenticate: whoami is %s", whoami) - if whoami is None: - raise RuntimeError('LDAP authenticate: anonymous bind') + options, 'bind-user', params), bind_password) + try: + whoami = l.whoami_s() + except ldap.PROTOCOL_ERROR: + # The "Who am I?" extended operation is not supported by this LDAP server + pass + else: + log.debug("LDAP authenticate: whoami is %s", whoami) + if whoami is None: + raise RuntimeError('LDAP authenticate: anonymous bind') except Exception: log.warning('LDAP authenticate: bind exception', exc_info=True) return (failure_mode, '', '')