ok - local provider has a stable name ok - local hashed password authenticates ok - local wrong password is safe ok - empty local password is rejected ok - local provider rejects non-local row source ok - legacy local password authenticates ok - legacy password requests rehash ok - LDAP technical failover reaches second URI ok - LDAP provider has a stable name ok - LDAP exact security key enables startTLS ok - LDAP exact CA key is set before connect ok - LDAP user base DN takes precedence ok - LDAP username is filter escaped ok - LDAP service bind precedes user bind ok - LDAP network timeout is applied as a bounded integer ok - LDAP time limit option is applied when available ok - LDAP search is bounded to two results and the remaining deadline ok - non-positive LDAP timeout clamps to one second ok - oversized LDAP timeout clamps to thirty seconds ok - user rejection does not fail over ok - server-side nested-group matching authenticates without memberOf data ok - LDAP failover observes one request-wide deadline ok - LDAP does not start a new operation with less than one second left ok - LDAP empty password does not connect ok - binary objectGUID is canonicalized ok - LDAP missing external ID fails authentication ok - LDAP missing external ID attribute fails configuration ok - technical user-bind failure reaches second URI ok - LDAPS mode rejects a cleartext ldap URI before connecting ok - string false explicitly disables certificate verification ok - manager delegates to its explicit provider ok - manager has no implicit fallback ALL PASSED