ACCESS_REFUSED - login failed when LDAP token expires mid‑session
0 reputation · 11 Feb 2023, 22:41 UTC
ACCESS_REFUSED - login failed
LDAP authentication backend
The goal is to understand how RabbitMQ handles credential expiration for external authentication sources such as LDAP or OAuth2. When a user’s token is revoked or expires, RabbitMQ logs ACCESS_REFUSED - login failed for any new connection attempts, but the behavior for already‑established connections is unclear.
Constraints include RabbitMQ’s internal authentication backend lacking password rotation or TTL support, and the fact that external backends only validate credentials at the start of a connection. Existing connections may therefore remain open even after the external credential becomes invalid, potentially violating least‑privilege requirements.
Unresolved decision: Does RabbitMQ provide any mechanism—built‑in or plugin—to automatically terminate or re‑authenticate existing connections when the external token expires or is revoked?
Specific questions:
- When an LDAP token expires, does RabbitMQ automatically close all open channels for that user, or must the application detect and reconnect?
- Is there a configuration option or plugin that enforces token introspection on each message or at regular intervals to enforce credential validity?
- What impact does this behavior have on compliance frameworks that require immediate revocation of access upon credential expiration?