Re: Directory Administrator Participation

Guido Trotter <[email protected]>
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
On Mon, Jun 23, 2003 at 04:57:41PM -0500, Manuel Amador (Rudd-O) wrote:

Hi,

> Well, I once got a patch to not store passwords in the disk, but i REALLY don't
> remember where I put it so I lost it (that's why I encourage everyone to post
> their patches to the patch manager, so I dont have to manage them myself hehe).
> 
> Now, I think there is no point in storing the passwords encrypted on disk, since
> anyone with the algorithm (OSS software process anyone?) will be able to get the
> password anyway if they have physical access to the disk.  See above.
> 

This is perfectly right. Better to have the password stored in clear text
than to encrypt them in a way that anyone can actually read. Anyway maybe
there can be some palliative solution:

The first one, already implemented, is to write the file in a way other
users cannot read it (the ~/.directory_administrator directory gets created 
with 0700 permission).

Another one would be to have the option not to remember the password, and
to ask it at connect time.

The last can be to protect all the password in the file with a "master
password", which is requested to use any connection. (but I think the
second one is better)

Bye,

Guido



-------------------------------------------------------
This SF.Net email is sponsored by: INetU
Attention Web Developers & Consultants: Become An INetU Hosting Partner.
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission!
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.