LDAP: Allow setting minimum TLS version and accepted ciphers (#63646)
* update ldap library and use go module path * add TLS min version and accepted min TLS version * set default min ver to library default * set default min ver to library default * add cipher list to toml * Update pkg/services/ldap/settings.go Co-authored-by: Karl Persson <kalle.persson@grafana.com> * Apply suggestions from code review Co-authored-by: Christopher Moyer <35463610+chri2547@users.noreply.github.com> * lint --------- Co-authored-by: Karl Persson <kalle.persson@grafana.com> Co-authored-by: Christopher Moyer <35463610+chri2547@users.noreply.github.com>
This commit is contained in:
co-authored by
Karl Persson
Christopher Moyer
parent
2ee73ad7f9
commit
7e97dbde65
@@ -1,7 +1,7 @@
|
||||
package ldap
|
||||
|
||||
import (
|
||||
"os"
|
||||
"crypto/tls"
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -12,11 +12,14 @@ func TestReadingLDAPSettings(t *testing.T) {
|
||||
config, err := readConfig("testdata/ldap.toml")
|
||||
assert.Nil(t, err, "No error when reading ldap config")
|
||||
assert.EqualValues(t, "127.0.0.1", config.Servers[0].Host)
|
||||
assert.EqualValues(t, "tls1.3", config.Servers[0].MinTLSVersion)
|
||||
assert.EqualValues(t, uint16(tls.VersionTLS13), config.Servers[0].minTLSVersion)
|
||||
assert.EqualValues(t, []string{"TLS_CHACHA20_POLY1305_SHA256", "TLS_AES_128_GCM_SHA256"}, config.Servers[0].TLSCiphers)
|
||||
assert.ElementsMatch(t, []uint16{tls.TLS_CHACHA20_POLY1305_SHA256, tls.TLS_AES_128_GCM_SHA256}, config.Servers[0].tlsCiphers)
|
||||
}
|
||||
|
||||
func TestReadingLDAPSettingsWithEnvVariable(t *testing.T) {
|
||||
err := os.Setenv("ENV_PASSWORD", "MySecret")
|
||||
require.NoError(t, err)
|
||||
t.Setenv("ENV_PASSWORD", "MySecret")
|
||||
|
||||
config, err := readConfig("testdata/ldap.toml")
|
||||
require.NoError(t, err)
|
||||
|
||||
Reference in New Issue
Block a user