Profile Password Security
Gabriel Donnell <[email protected]>
| Newsgroups | gmane.network.directoryadmin |
|---|---|
| Message-ID | <[email protected]> |
Hello Guido, You provided some good alternatives to protecting the passwords for the profiles. Below are my comments. Directory/File Access By default, Red Hat Linux creates home directories that only grant access to the owner. Therefore, on Red Hat Linux, only the owner and root should be able to view the passwords for the DA profiles. The key issue in the previous sentence is "root should be able to view the passwords for the DA profiles." I am not comfortable with root having access to view the passwords. Although I am big proponent of protecting file access with permissions, I do not prefer that as a method to protect clear text passwords. Master Password Protecting the passwords for the profiles with one master password that decrypts the password file for a given DA process session is a good alternative. As long as the segmentation core dump will not expose the decrypted file. The downside is that the master password would need to be entered for each separate simultaneous DA process. I run multiple simultaneous DA sessions for different profiles. If I have to enter the master password for each DA session, then there is no need to store the password for the profile. I may as well enter the password for the profile connection. For convenience, DA could be enhanced to support single sign on with the master password. That way a single DA process can open multiple simultaneous connection windows for different LDAP accounts or profiles. Disable Password Storing An option to not use stored passwords seems to be the best easiest alternative to implement. I do not mind entering the profile password for each connection. I tried leaving the profile password blank to see if DA would prompt me for the password. However, it does not. It gives an "Access denied" error message. I am sure there are several good alternatives to implement. I would not mind helping code the resolution. However, I need to familiarize myself with the DA code as Manuel suggested. I plan to do this soon. Regards, Gabriel Donnell __________________________________ Do you Yahoo!? SBC Yahoo! DSL - Now only $29.95 per month! http://sbc.yahoo.com
(unnamed)
(message/rfc822, 4.7 KB) - not displayed