Re: PAM Authentication Patch
"Mark D. Baushke" <[email protected]>
| Newsgroups | gmane.comp.bug-tracking.gnats.general |
|---|---|
| Message-ID | <[email protected]> |
Chad Walstrom <[email protected]> writes: > Chad Walstrom wrote: > > We should make it abundantly clear in the > > documentation that use of PAM authentication > > should be thoroughly protected. If such > > measures cannot be taken, don't enable PAM. > > Additionally, we can't always assume that > because something uses PAM, it'll authentication > against system accounts. There are dbm modules, > ldap modules, etc. that can be used for account > management. While I do understand that it is *possible* to enable PAM and not endanger other applications or systems. I also understand that very few people or organizations will consider keeping such things separate in such a safe configuration unless the documentation clearly states that there are security implications to be considered. Yes, I am being paranoid. right now it seems fairly clear that gnatsd authentication is not very strongly protected. Folks are more likely to believe something is 'secure' if it can talk to PAM even though there may be explicit basis for that belief. -- Mark