Re: PAM Authentication Patch

"Mark D. Baushke" <[email protected]>
Newsgroups gmane.comp.bug-tracking.gnats.general
Message-ID <[email protected]>
Chad Walstrom <[email protected]> writes:

> Chad Walstrom wrote:
> > We should make it abundantly clear in the
> > documentation that use of PAM authentication
> > should be thoroughly protected. If such
> > measures cannot be taken, don't enable PAM.
> 
> Additionally, we can't always assume that
> because something uses PAM, it'll authentication
> against system accounts. There are dbm modules,
> ldap modules, etc. that can be used for account
> management.

While I do understand that it is *possible* to
enable PAM and not endanger other applications or
systems. I also understand that very few people or
organizations will consider keeping such things
separate in such a safe configuration unless the
documentation clearly states that there are
security implications to be considered.

Yes, I am being paranoid. right now it seems
fairly clear that gnatsd authentication is not
very strongly protected. Folks are more likely to
believe something is 'secure' if it can talk to
PAM even though there may be explicit basis for
that belief.

	-- Mark
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.