From 71c36c5bb48ad70ec6f079bbedd6114b769805fa Mon Sep 17 00:00:00 2001 From: Michael Kozono Date: Fri, 9 Jun 2017 11:43:07 -0700 Subject: [PATCH] Add warning about certificate verification on load --- config/initializers/1_settings.rb | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/config/initializers/1_settings.rb b/config/initializers/1_settings.rb index 20fe92dd6b3..201a1d062b9 100644 --- a/config/initializers/1_settings.rb +++ b/config/initializers/1_settings.rb @@ -153,7 +153,16 @@ if Settings.ldap['enabled'] || Rails.env.test? # Certificates are not verified for backwards compatibility. # This default should be flipped to true in 9.5. - server['verify_certificates'] = false if server['verify_certificates'].nil? + if server['verify_certificates'].nil? + server['verify_certificates'] = false + + message = <<-MSG.strip_heredoc + LDAP SSL certificate verification is disabled for backwards-compatibility. + Please add the "verify_certificates" option to gitlab.yml for each LDAP + server. Certificate verification will be enabled by default in GitLab 9.5. + MSG + Rails.logger.warn(message) + end end end