If LDAP servers supports anonymous sessions, then a login with
an username (existing in LDAP) and empty password becomes
possible.
The problem is that call to InitialDirContext constructor doesn't
require an AD bind and if Context.SECURITY_CREDENTIALS contains
empty string authentication method 'none' (anonymous) is used.
Affected: Rundeck 1.3+ with implemented
http://rundeck.lighthouseapp.com/projects/59277-development/tickets...
See commit
https://github.com/coiouhkc/rundeck/commit/a8f999efc66d2131800fd53e...
Possible workaround is:
JettyCachingLdapLoginModule.java, ll.528-534
String pass = (String) password;
Hashtable environment = getEnvironment();
environment.put(Context.SECURITY_PRINCIPAL, userDn);
environment.put(Context.SECURITY_CREDENTIALS,
(pass.trim().isEmpty() ? "password_that_would_be never_used" :
pass));
DirContext dirContext = new InitialDirContext(environment);