Profile Password Security

Gabriel Donnell <[email protected]>
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
Hello Guido,

You provided some good alternatives to protecting the passwords for the
profiles.  Below are my comments.

Directory/File Access
  By default, Red Hat Linux creates home directories that only grant access
  to the owner.  Therefore, on Red Hat Linux, only the owner and root should
  be able to view the passwords for the DA profiles.

  The key issue in the previous sentence is "root should be able to view the
  passwords for the DA profiles."  I am not comfortable with root having
  access to view the passwords.

  Although I am big proponent of protecting file access with permissions, I
  do not prefer that as a method to protect clear text passwords.

Master Password
  Protecting the passwords for the profiles with one master password that
  decrypts the password file for a given DA process session is a good
  alternative.  As long as the segmentation core dump will not expose the
  decrypted file.

  The downside is that the master password would need to be entered for
  each separate simultaneous DA process.  I run multiple simultaneous DA
  sessions for different profiles.  If I have to enter the master password
  for each DA session, then there is no need to store the password for the
  profile.  I may as well enter the password for the profile connection.

  For convenience, DA could be enhanced to support single sign on with the
  master password.  That way a single DA process can open multiple
  simultaneous connection windows for different LDAP accounts or profiles.

Disable Password Storing
  An option to not use stored passwords seems to be the best easiest
  alternative to implement.  I do not mind entering the profile password
  for each connection.

  I tried leaving the profile password blank to see if DA would prompt me
  for the password.  However, it does not.  It gives an "Access denied"
  error message.

I am sure there are several good alternatives to implement.  I would not
mind helping code the resolution.  However, I need to familiarize myself
with the DA code as Manuel suggested.  I plan to do this soon.

Regards,
Gabriel Donnell

__________________________________
Do you Yahoo!?
SBC Yahoo! DSL - Now only $29.95 per month!
http://sbc.yahoo.com
(unnamed) (message/rfc822, 4.7 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.