Re: PAM Authentication Patch

Chad Walstrom <[email protected]>
Newsgroups gmane.comp.bug-tracking.gnats.general
Message-ID <[email protected]>
Mark D. Baushke wrote:
> The biggest problem I have with PAM support for gnatsd is that you
> will now be sending a credential across the network in the clear which
> is presumably able to be used as a credential outside of gnats. This
> could lead to a simple password replay attack to gain access to
> systems by unauthorized individuals or their agents.
> 
> I strongly urge you to first include and enable SSL (or TLS) support
> in gantsd before you allow PAM to be used to authorize connections.

Agreed. This is definitely something that should get on the TODO list
for gnatsd.  Alternatively, there are ways of tunneling TCP connections
over secure channels, so I don't think the lack of gnutls integration
should exclude the PAM patch.

We should make it abundantly clear in the documentation that use of PAM
authentication should be thoroughly protected.  If such measures cannot
be taken, don't enable PAM.

-- 
Chad Walstrom <[email protected]>           http://www.wookimus.net/
           assert(expired(knowledge)); /* core dump */

_______________________________________________
Help-gnats mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/help-gnats
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFA1cu8DMcLGCBsWv0RAnKYAJ9C+94X+1b00I86zv7EmQC5FUG2AwCdHg2t
qiZOvClV2HbmeF7NgX3yKfY=
=4WwS
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.