[#1116] Default the java-class of a new LDAP connection handler to LDAPConnectionHandler2 - #1124
Merged
vharseko merged 1 commit intoSep 30, 2026
Conversation
…ection handler to LDAPConnectionHandler2 dsconfig create-connection-handler --type ldap wrote the legacy org.opends.server.protocols.ldap.LDAPConnectionHandler into the new entry, because java-class is mandatory and the client materialises its default. Every shipped LDAP listener runs on org.forgerock.opendj.reactive.LDAPConnectionHandler2, and SASL EXTERNAL, SASL confidentiality/integrity and the authmethod=SSL bind rule only work there. Make it the default; existing entries carry the class explicitly and are unchanged, and the legacy class stays available through an explicit --set java-class. Fixes OpenIdentityPlatform#1116
maximthomas
approved these changes
Sep 30, 2026
maximthomas
left a comment
Contributor
There was a problem hiding this comment.
praise: The fix changes the one value that decides the class of a dsconfig-created handler, and the test checks what is stored and what runs.
LDAPConnectionHandlerConfiguration.xml:83: thejava-classdefault is the only sourceLDAPManagedObject.encodePropertyuses for this mandatory property oncreate-connection-handler. Existing entries carry the class explicitly and stay as they are.testCreatedHandlerDefaultsToLDAPConnectionHandler2asserts both the persistedds-cfg-java-class(TestLDAPConnectionHandler.java:389) and the class of the registered handler (:399), and deletes the handler infinally.- The description names the properties
LDAPConnectionHandler2does not apply (use-tcp-keep-alive,use-tcp-no-delay,buffer-size,num-request-handlers, bind-sideallow-tcp-reuse-address) and links #1119. A grep oforg/forgerock/opendj/reactive/at this head confirms the list is complete.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1116
Problem
dsconfig create-connection-handler --type ldapcreates a handler on the legacyorg.opends.server.protocols.ldap.LDAPConnectionHandler, while every shipped LDAP listener (LDAP Connection Handler,LDAPS Connection Handler, the administration connector) runs onorg.forgerock.opendj.reactive.LDAPConnectionHandler2.java-classis mandatory, soLDAPManagedObject.encodePropertywrites its effective value, i.e. the default fromLDAPConnectionHandlerConfiguration.xml, into the new entry.On the legacy class SASL EXTERNAL fails with
INVALID_CREDENTIALS, a SASL bind that negotiates confidentiality or integrity ends in aClassCastException, and the ACI bind ruleauthmethod="SSL"never matches: all three require anLDAPClientConnection2.Change
LDAPConnectionHandlerConfiguration.xml: the default ofjava-classis noworg.forgerock.opendj.reactive.LDAPConnectionHandler2.--set java-class:org.opends.server.protocols.ldap.LDAPConnectionHandler. The generated configuration reference picks the new default up from the XML.Note for reviewers:
LDAPConnectionHandler2does not applyuse-tcp-keep-alive,use-tcp-no-delay,buffer-size,num-request-handlersand the bind side ofallow-tcp-reuse-address. That already holds for the shipped listeners; with this change it also holds for handlers created withdsconfig. It is tracked separately in #1119.Tests
TestLDAPConnectionHandler#testCreatedHandlerDefaultsToLDAPConnectionHandler2creates a handler withdsconfig create-connection-handler --type ldapand nojava-class, then checks both the storedds-cfg-java-classand the class of the handler the server registered.expected [org.forgerock.opendj.reactive.LDAPConnectionHandler2] but found [org.opends.server.protocols.ldap.LDAPConnectionHandler].org/opends/server/protocols/**,SASLOverTLSTestCaseandExternalSASLMechanismHandlerTestCasepass (1149 tests). Three classes of that run (LDAPv2TestCase,TestBindResponseProtocolOp,TestDeleteResponseProtocolOp) failed to start the server on an admin port 65534 held by another process and pass when re-run on their own (26 tests).