Hey, thank you for your continued work on providing a container image for OpenLDAP.
I’m currently building a testcontainers wrapper around this image to test against/mock OpenLDAP 2.x, but there seems to be a issue with hash handling during bootstrap in openldap:2.6.10-alpha (image digest sha256:fb0e84e744d54135ae1bb9b0f34d858b4219830c3f0536819f505ebe7a5d3918).
Specifically, it appears that environment variables are reparsed at some point, causing $ characters in their values to be interpreted as variable references.
For example, passing the following environment variable:
OPENLDAP_BOOTSTRAP_DATA_ROOT_PASSWORD_HASHED={ARGON2}$argon2id$v=19$m=65536,t=3,p=4$pHysLBm/kFPLuIQaKZUdIw$J9K+g6AIsHumbrjHiKBL3+aIVYAa+mBl3KNDiFiYVHA
results in the following database value, as reported by slapcat -n 0 inside the running container:
olcRootDN: cn=admin,[my prefix]
olcRootPW:: e0FSR09OMn0kYXJnb24yaWQkdj0xOSRtPTY1NTM2LHQ9MyxwPTQkcEh5c0xCbS9rRlBMdUlRYUtaVWRJdytnNkFJc0h1bWJyakhpS0JMMythSVZZQWErbUJsM\
0tORGlGaVlWSEE=
This decodes to:
{ARGON2}$argon2id$v=19$m=7168,t=5,p=1$cX6Fzhw//Y4fL4q1iI3gEA$KGbo9cKg8CMCEsPoooLp4UQaPAub8rUiubRma3VpIdw
The problem is more clearly visible when comparing the expected and stored values:
{ARGON2}$argon2id$v=19$m=65536,t=3,p=4$pHysLBm/kFPLuIQaKZUdIw$J9K+g6AIsHumbrjHiKBL3+aIVYAa+mBl3KNDiFiYVHA
{ARGON2}$argon2id$v=19$m=65536,t=3,p=4$pHysLBm/kFPLuIQaKZUdIw+g6AIsHumbrjHiKBL3+aIVYAa+mBl3KNDiFiYVHA
It appears that $J9K is being interpreted and removed. This corrupts the digest by removing the separator between the salt and the hash.
My current workaround is to escape every $ character as \$:
strings.ReplaceAll(digest, "$", "\\$")
This resolves the issue for now.
Unfortunately, I haven’t been able to determine exactly where this happens in the bootstrap code. It appears to originate somewhere in the helper scripts provided by the base image.
Hey, thank you for your continued work on providing a container image for OpenLDAP.
I’m currently building a testcontainers wrapper around this image to test against/mock OpenLDAP 2.x, but there seems to be a issue with hash handling during bootstrap in
openldap:2.6.10-alpha(image digestsha256:fb0e84e744d54135ae1bb9b0f34d858b4219830c3f0536819f505ebe7a5d3918).Specifically, it appears that environment variables are reparsed at some point, causing
$characters in their values to be interpreted as variable references.For example, passing the following environment variable:
results in the following database value, as reported by
slapcat -n 0inside the running container:This decodes to:
The problem is more clearly visible when comparing the expected and stored values:
It appears that
$J9Kis being interpreted and removed. This corrupts the digest by removing the separator between the salt and the hash.My current workaround is to escape every
$character as\$:This resolves the issue for now.
Unfortunately, I haven’t been able to determine exactly where this happens in the bootstrap code. It appears to originate somewhere in the helper scripts provided by the base image.