Uploaded image for project: 'Directory Studio'
  1. Directory Studio
  2. DIRSTUDIO-1255

ApacheDS Does Not Send TLS HostSNI Extension Information in Requests

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • 2.0.0-M15
    • None
    • studio-ldapservers
    • Pop!_OS ( Ubuntu ) 20.04

    Description

      I have an LDAP server that is hosted behind a Traefik reverse proxy that is used to generate trusted TLS certificates that are terminated before hitting the LDAP server. The Traefik proxy uses the Host SNI TLS extension in order to determine whether or not to route the request to the LDAP server or something else, but ApacheDS Studio does not send the Host SNI data in its request which means that Traefik cannot determine that the request is supposed to be routed to the LDAP server.

       

      Connecting to the LDAP server works fine using curl because curl sends the server name data in its request. I used Wireshark to double-check the request coming from ApacheDS Studio and verified that the server name extension was not present on the TLS request.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              zicklag Zicklag
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated: