1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Benjamin Smee wrote: |
5 |
> The typical way, perhaps, but its fairly insecure imo, I don't like |
6 |
> giving out more information then I have to and exposing my DIT to anon |
7 |
> binds is something that I dislike. Of course proper layout of the DIT |
8 |
> means that there is nothing sensitive being exposed, but I still don't |
9 |
> like giving out ANY information to anon users. My level of paranoia is |
10 |
> not always appropriate for others though :) |
11 |
|
12 |
Allowing userPassword for auth means they can't read the attribute's value, but apply authentication |
13 |
to it. So, you are exposing no information. |
14 |
|
15 |
- -- |
16 |
Arturo "Buanzo" Busleiman - www.buanzo.com.ar |
17 |
Consultor en Seguridad Informatica |
18 |
President, Open Information System Security Group - Argentina |
19 |
-----BEGIN PGP SIGNATURE----- |
20 |
Version: GnuPG v1.4.1 (GNU/Linux) |
21 |
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org |
22 |
|
23 |
iD8DBQFC5nB+AlpOsGhXcE0RAhL9AJ416fGcHhWerJwBwb4sJ3/788/2KQCff95f |
24 |
5NCuJIagpDQmUYQoP9bktmI= |
25 |
=t8cs |
26 |
-----END PGP SIGNATURE----- |
27 |
-- |
28 |
gentoo-server@g.o mailing list |