Skip to content

ldap: support remapping roles between the LDAP/AD server and CockroachDB roles #125095

Open
@dikshant

Description

@dikshant

In some cases CockroachDB roles and LDAP/AD roles may not be the same. In such cases we need a setting that specifies how a role is remapped.

The exact setting/UX of this needs further discussion but perhaps we can reuse the pg ident config we have.

Jira issue: CRDB-39231

Epic CRDB-21590

Metadata

Metadata

Assignees

Labels

A-authenticationPertains to authn subsystemsA-securityC-enhancementSolution expected to add code/behavior + preserve backward-compat (pg compat issues are exception)P-3Issues/test failures with no fix SLAT-product-security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions