Skip to content

[#1116] Default the java-class of a new LDAP connection handler to LDAPConnectionHandler2 - #1124

Merged
vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:fix/1116-ldap-handler-default-class
Sep 30, 2026
Merged

vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:fix/1116-ldap-handler-default-class

Conversation

@vharseko

@vharseko vharseko commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Fixes #1116

Problem

dsconfig create-connection-handler --type ldap creates a handler on the legacy org.opends.server.protocols.ldap.LDAPConnectionHandler, while every shipped LDAP listener (LDAP Connection Handler, LDAPS Connection Handler, the administration connector) runs on org.forgerock.opendj.reactive.LDAPConnectionHandler2. java-class is mandatory, so LDAPManagedObject.encodeProperty writes its effective value, i.e. the default from LDAPConnectionHandlerConfiguration.xml, into the new entry.

On the legacy class SASL EXTERNAL fails with INVALID_CREDENTIALS, a SASL bind that negotiates confidentiality or integrity ends in a ClassCastException, and the ACI bind rule authmethod="SSL" never matches: all three require an LDAPClientConnection2.

Change

  • LDAPConnectionHandlerConfiguration.xml: the default of java-class is now org.forgerock.opendj.reactive.LDAPConnectionHandler2.
  • Existing entries carry the class explicitly, so nothing changes for them. The legacy class stays available through an explicit --set java-class:org.opends.server.protocols.ldap.LDAPConnectionHandler. The generated configuration reference picks the new default up from the XML.
  • Migrating existing legacy entries on upgrade is out of scope, as stated in the issue.

Note for reviewers: LDAPConnectionHandler2 does not apply use-tcp-keep-alive, use-tcp-no-delay, buffer-size, num-request-handlers and the bind side of allow-tcp-reuse-address. That already holds for the shipped listeners; with this change it also holds for handlers created with dsconfig. It is tracked separately in #1119.

Tests

TestLDAPConnectionHandler#testCreatedHandlerDefaultsToLDAPConnectionHandler2 creates a handler with dsconfig create-connection-handler --type ldap and no java-class, then checks both the stored ds-cfg-java-class and the class of the handler the server registered.

  • Before the XML change the test fails with expected [org.forgerock.opendj.reactive.LDAPConnectionHandler2] but found [org.opends.server.protocols.ldap.LDAPConnectionHandler].
  • After it: org/opends/server/protocols/**, SASLOverTLSTestCase and ExternalSASLMechanismHandlerTestCase pass (1149 tests). Three classes of that run (LDAPv2TestCase, TestBindResponseProtocolOp, TestDeleteResponseProtocolOp) failed to start the server on an admin port 65534 held by another process and pass when re-run on their own (26 tests).

…ection handler to LDAPConnectionHandler2

dsconfig create-connection-handler --type ldap wrote the legacy
org.opends.server.protocols.ldap.LDAPConnectionHandler into the new entry,
because java-class is mandatory and the client materialises its default.
Every shipped LDAP listener runs on
org.forgerock.opendj.reactive.LDAPConnectionHandler2, and SASL EXTERNAL,
SASL confidentiality/integrity and the authmethod=SSL bind rule only work
there. Make it the default; existing entries carry the class explicitly and
are unchanged, and the legacy class stays available through an explicit
--set java-class.

Fixes OpenIdentityPlatform#1116

@maximthomas maximthomas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

praise: The fix changes the one value that decides the class of a dsconfig-created handler, and the test checks what is stored and what runs.

  • LDAPConnectionHandlerConfiguration.xml:83: the java-class default is the only source LDAPManagedObject.encodeProperty uses for this mandatory property on create-connection-handler. Existing entries carry the class explicitly and stay as they are.
  • testCreatedHandlerDefaultsToLDAPConnectionHandler2 asserts both the persisted ds-cfg-java-class (TestLDAPConnectionHandler.java:389) and the class of the registered handler (:399), and deletes the handler in finally.
  • The description names the properties LDAPConnectionHandler2 does not apply (use-tcp-keep-alive, use-tcp-no-delay, buffer-size, num-request-handlers, bind-side allow-tcp-reuse-address) and links #1119. A grep of org/forgerock/opendj/reactive/ at this head confirms the list is complete.

@vharseko
vharseko merged commit d0ce1d7 into OpenIdentityPlatform:master Sep 30, 2026
17 checks passed
@vharseko
vharseko deleted the fix/1116-ldap-handler-default-class branch September 30, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug java Changes to Java sources protocol LDAP protocol extensions, controls and RFC support tests Test suites: fixing, enabling, un-disabling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dsconfig create-connection-handler --type ldap creates the legacy LDAPConnectionHandler, not the LDAPConnectionHandler2 the server ships with

2 participants