From c56c44c5cee93fd23b13f4fdaf0254ae7a7353c2 Mon Sep 17 00:00:00 2001 From: Michael Miceli Date: Wed, 22 Jul 2026 06:24:48 -0400 Subject: [PATCH] Fix LDAP_ACCESSLOG_ADMIN_PASSWORD variable assignment (#94986) * Fix LDAP_ACCESSLOG_ADMIN_PASSWORD variable assignment The README specifies `LDAP_ACCESSLOG_ADMIN_PASSWORD` as the variable controlling admin access to the accesslog database, but the script is sourcing the value from `LDAP_ACCESSLOG_PASSWORD`. This change makes the assignment consistent with all other variables in this block, and match the documentation. Signed-off-by: Michael Miceli * Set default LDAP admin password in libopenldap.sh Signed-off-by: Michael Miceli * Update default LDAP_ACCESSLOG_ADMIN_PASSWORD value Signed-off-by: Michael Miceli * Update README.md Updated documentation to match environment variable default changes introduced in 3edc8683807dfa809e57c6b9c4fd2bf2f2f13483 Signed-off-by: Michael Miceli --------- Signed-off-by: Michael Miceli --- .../debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh | 2 +- bitnami/openldap/README.md | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/bitnami/openldap/2.6/debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh b/bitnami/openldap/2.6/debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh index 110679338d71..dbdb4242ea63 100644 --- a/bitnami/openldap/2.6/debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh +++ b/bitnami/openldap/2.6/debian-12/rootfs/opt/bitnami/scripts/libopenldap.sh @@ -100,7 +100,7 @@ export LDAP_ACCESSLOG_LOGOLD="${LDAP_ACCESSLOG_LOGOLD:-(objectClass=*)}" export LDAP_ACCESSLOG_LOGOLDATTR="${LDAP_ACCESSLOG_LOGOLDATTR:-objectClass}" export LDAP_ACCESSLOG_ADMIN_USERNAME="${LDAP_ACCESSLOG_ADMIN_USERNAME:-admin}" export LDAP_ACCESSLOG_ADMIN_DN="${LDAP_ACCESSLOG_ADMIN_USERNAME/#/cn=},${LDAP_ACCESSLOG_DB:-cn=accesslog}" -export LDAP_ACCESSLOG_ADMIN_PASSWORD="${LDAP_ACCESSLOG_PASSWORD:-}" +export LDAP_ACCESSLOG_ADMIN_PASSWORD="${LDAP_ACCESSLOG_ADMIN_PASSWORD:-}" export LDAP_ENABLE_SYNCPROV="${LDAP_ENABLE_SYNCPROV:-no}" export LDAP_SYNCPROV_CHECKPPOINT="${LDAP_SYNCPROV_CHECKPPOINT:-100 10}" export LDAP_SYNCPROV_SESSIONLOG="${LDAP_SYNCPROV_SESSIONLOG:-100}" diff --git a/bitnami/openldap/README.md b/bitnami/openldap/README.md index c93bdcec72eb..da57fa28a2b0 100644 --- a/bitnami/openldap/README.md +++ b/bitnami/openldap/README.md @@ -59,11 +59,11 @@ The Bitnami Docker OpenLDAP can be easily setup with the following environment v - `LDAP_PORT_NUMBER`: The port OpenLDAP is listening for requests. Privileged port is supported (e.g. `389`). Default: **1389** (non privileged port). - `LDAP_ROOT`: LDAP baseDN (or suffix) of the LDAP tree. Default: **dc=example,dc=org** - `LDAP_ADMIN_USERNAME`: LDAP database admin user. Default: **admin** -- `LDAP_ADMIN_PASSWORD`: LDAP database admin password. Default: **adminpassword** +- `LDAP_ADMIN_PASSWORD`: LDAP database admin password. No defaults. - `LDAP_ADMIN_PASSWORD_FILE`: Path to a file that contains the LDAP database admin user password. This will override the value specified in `LDAP_ADMIN_PASSWORD`. No defaults. - `LDAP_CONFIG_ADMIN_ENABLED`: Whether to create a configuration admin user. Default: **no**. - `LDAP_CONFIG_ADMIN_USERNAME`: LDAP configuration admin user. This is separate from `LDAP_ADMIN_USERNAME`. Default: **admin**. -- `LDAP_CONFIG_ADMIN_PASSWORD`: LDAP configuration admin password. Default: **configpassword**. +- `LDAP_CONFIG_ADMIN_PASSWORD`: LDAP configuration admin password. No defaults. - `LDAP_CONFIG_ADMIN_PASSWORD_FILE`: Path to a file that contains the LDAP configuration admin user password. This will override the value specified in `LDAP_CONFIG_ADMIN_PASSWORD`. No defaults. - `LDAP_USERS`: Comma separated list of LDAP users to create in the default LDAP tree. Default: **user01,user02** - `LDAP_PASSWORDS`: Comma separated list of passwords to use for LDAP users. Default: **bitnami1,bitnami2** @@ -78,7 +78,7 @@ The Bitnami Docker OpenLDAP can be easily setup with the following environment v - `LDAP_CUSTOM_SCHEMA_FILE`: Location of a custom internal schema file that could not be added as custom ldif file (i.e. containing some `structuralObjectClass`). Default is **/schema/custom.ldif**" - `LDAP_CUSTOM_SCHEMA_DIR`: Location of a directory containing custom internal schema files that could not be added as custom ldif files (i.e. containing some `structuralObjectClass`). This can be used in addition to or instead of `LDAP_CUSTOM_SCHEMA_FILE` (above) to add multiple schema files. Default: **/schemas** - `LDAP_ULIMIT_NOFILES`: Maximum number of open file descriptors. Default: **1024**. -- `LDAP_ALLOW_ANON_BINDING`: Allow anonymous bindings to the LDAP server. Default: **yes**. +- `LDAP_ALLOW_ANON_BINDING`: Allow anonymous bindings to the LDAP server. Default: **no**. - `LDAP_LOGLEVEL`: Set the loglevel for the OpenLDAP server (see for possible values). Default: **256**. - `LDAP_PASSWORD_HASH`: Hash to be used in generation of user passwords. Must be one of {SSHA}, {SHA}, {SMD5}, {MD5}, {CRYPT}, and {CLEARTEXT}. Default: **{SSHA}**. - `LDAP_CONFIGURE_PPOLICY`: Enables the ppolicy module and creates an empty configuration. Default: **no**. @@ -130,7 +130,7 @@ This overlay can record accesses to a given backend database on another database - `LDAP_ENABLE_ACCESSLOG`: Enables the accesslog module with the following configuration defaults unless specified otherwise. Default: **no**. - `LDAP_ACCESSLOG_ADMIN_USERNAME`: Admin user for accesslog database. Default: **admin**. -- `LDAP_ACCESSLOG_ADMIN_PASSWORD`: Admin password for accesslog database. Default: **accesspassword**. +- `LDAP_ACCESSLOG_ADMIN_PASSWORD`: Admin password for accesslog database. No defaults. - `LDAP_ACCESSLOG_DB`: The DN (Distinguished Name) of the database where the access log entries will be stored. Will only be applied with `LDAP_ENABLE_ACCESSLOG` active. Default: **cn=accesslog**. - `LDAP_ACCESSLOG_LOGOPS`: Specify which types of operations to log. Valid aliases for common sets of operations are: writes, reads, session or all. Will only be applied with `LDAP_ENABLE_ACCESSLOG` active. Default: **writes**. - `LDAP_ACCESSLOG_LOGSUCCESS`: Whether successful operations should be logged. Will only be applied with `LDAP_ENABLE_ACCESSLOG` active. Default: **TRUE**.