Elytron LDAP Logging Squashes Authentication Exceptions

Solution Verified - Updated

Environment

  • Red Hat JBoss Enterprise Applications Platform (EAP)
    • 7.1+
  • Elytron Security
  • Lightweight Directory Access Protocol (LDAP) or Microsoft Active Directory Lightweight Directory Service (AD)
  • Authentication failure
  • Debug logging enabled on "org.wildfly.security"

Issue

  • Log shows DEBUG [org.wildfly.security] (management task-1) Credential direct evidence verification failed. DN: [uid=testUser,ou=users,dc=example,dc=com] with no message or stack trace.

Resolution

This issue is resolved in JBoss EAP 7.2.8 release.

Root Cause

There is an error in logging code in the exception handler where it was meant to print the exception, but it's being ignored.

Components
Category

This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.