Most enterprise directories still answer on the plain LDAP port and expect the client to upgrade the connection. This release adds that upgrade and hardens the filters sent over it.
Transport
- StartTLS A configuration option negotiates StartTLS on the plain port with host-name verification. Plain, StartTLS and LDAPS are all configurable.
- Over the encrypted channel Anonymous connections and re-authentication both run after the upgrade. A trust-all socket factory exists for test environments only.
Filters and tests
- Injection-safe User input is sanitised before it enters a search filter.
- Structured logging replaces raw exceptions.
- Tested against a real directory Dockerised OpenLDAP tests cover direct bind and subtree search, with a login challenge or a password compare.
Directory integration is usually the first thing an IT department checks. It is now also encrypted the way they expect.