Welcome to mirror list, hosted at ThFree Co, Russian Federation.

gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDouwe Maan <douwe@gitlab.com>2017-08-31 10:33:59 +0300
committerDouwe Maan <douwe@gitlab.com>2017-08-31 10:33:59 +0300
commit073f6f0853d95e25eaf7f73163d051335caaa550 (patch)
tree87af44ce1a0a7aa8d33b12bdfc8baff82d8447c3 /config/initializers
parenta0b568463465f5c5e900896844a03989d1088704 (diff)
parentda6fede910f3812a8423ad4679839b6d680f9e73 (diff)
Merge branch 'mk-default-ldap-verify-certificates-secure' into 'master'
Default LDAP config verify_certificates to true Closes #33662 See merge request !13915
Diffstat (limited to 'config/initializers')
-rw-r--r--config/initializers/1_settings.rb17
1 files changed, 5 insertions, 12 deletions
diff --git a/config/initializers/1_settings.rb b/config/initializers/1_settings.rb
index abaabad5d65..360b72cdea3 100644
--- a/config/initializers/1_settings.rb
+++ b/config/initializers/1_settings.rb
@@ -155,18 +155,11 @@ if Settings.ldap['enabled'] || Rails.env.test?
server['encryption'] = 'simple_tls' if server['encryption'] == 'ssl'
server['encryption'] = 'start_tls' if server['encryption'] == 'tls'
- # Certificates are not verified for backwards compatibility.
- # This default should be flipped to true in 9.5.
- if server['verify_certificates'].nil?
- server['verify_certificates'] = false
-
- message = <<-MSG.strip_heredoc
- LDAP SSL certificate verification is disabled for backwards-compatibility.
- Please add the "verify_certificates" option to gitlab.yml for each LDAP
- server. Certificate verification will be enabled by default in GitLab 9.5.
- MSG
- Rails.logger.warn(message)
- end
+ # Certificate verification was added in 9.4.2, and defaulted to false for
+ # backwards-compatibility.
+ #
+ # Since GitLab 10.0, verify_certificates defaults to true for security.
+ server['verify_certificates'] = true if server['verify_certificates'].nil?
Settings.ldap['servers'][key] = server
end