Gentoo Archives: gentoo-server

From: Arturo 'Buanzo' Busleiman <buanzo@××××××××××.ar>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Re: Re: Practical user management with OpenLDAP?
Date: Tue, 26 Jul 2005 17:21:43
Message-Id: 42E6707E.70400@buanzo.com.ar
In Reply to: Re: [gentoo-server] Re: Re: Practical user management with OpenLDAP? by Benjamin Smee
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Benjamin Smee wrote:
5 > The typical way, perhaps, but its fairly insecure imo, I don't like
6 > giving out more information then I have to and exposing my DIT to anon
7 > binds is something that I dislike. Of course proper layout of the DIT
8 > means that there is nothing sensitive being exposed, but I still don't
9 > like giving out ANY information to anon users. My level of paranoia is
10 > not always appropriate for others though :)
11
12 Allowing userPassword for auth means they can't read the attribute's value, but apply authentication
13 to it. So, you are exposing no information.
14
15 - --
16 Arturo "Buanzo" Busleiman - www.buanzo.com.ar
17 Consultor en Seguridad Informatica
18 President, Open Information System Security Group - Argentina
19 -----BEGIN PGP SIGNATURE-----
20 Version: GnuPG v1.4.1 (GNU/Linux)
21 Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
22
23 iD8DBQFC5nB+AlpOsGhXcE0RAhL9AJ416fGcHhWerJwBwb4sJ3/788/2KQCff95f
24 5NCuJIagpDQmUYQoP9bktmI=
25 =t8cs
26 -----END PGP SIGNATURE-----
27 --
28 gentoo-server@g.o mailing list

Replies

Subject Author
[gentoo-server] IMAP Filtering Wendall Cada <wendallc@×××××.com>