Re: Profile Password Security

Guido Trotter <[email protected]>
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
On Tue, Jun 24, 2003 at 08:18:33PM -0700, Gabriel Donnell wrote:

Hi,

> Directory/File Access
>   By default, Red Hat Linux creates home directories that only grant access
>   to the owner.  Therefore, on Red Hat Linux, only the owner and root should
>   be able to view the passwords for the DA profiles.
> 
>   The key issue in the previous sentence is "root should be able to view the
>   passwords for the DA profiles."  I am not comfortable with root having
>   access to view the passwords.
> 
>   Although I am big proponent of protecting file access with permissions, I
>   do not prefer that as a method to protect clear text passwords.
> 

This kind of access is secured also in system which, by default, create 755
home directories, since DA would create his own ~/.directory_administrator
with 700 permission.

Anyway trying to be protected from root is no game. Simply: don't use DA in
a system whose administrator you don't trust. Any type of protection we can
implement can easily be passed by one with root privileges. Perhaps he
could change the directory administrator binary to save the password
somewhere, or he can sniff what you type on your keyboard, and the game is
over.

> Master Password
>   Protecting the passwords for the profiles with one master password that
>   decrypts the password file for a given DA process session is a good
>   alternative.  As long as the segmentation core dump will not expose the
>   decrypted file.
> 
>   The downside is that the master password would need to be entered for
>   each separate simultaneous DA process.  I run multiple simultaneous DA
>   sessions for different profiles.  If I have to enter the master password
>   for each DA session, then there is no need to store the password for the
>   profile.  I may as well enter the password for the profile connection.
> 
>   For convenience, DA could be enhanced to support single sign on with the
>   master password.  That way a single DA process can open multiple
>   simultaneous connection windows for different LDAP accounts or profiles.
> 

I'm against the master password solution, since absolutely doesn't help and
is quite complex to implement. 
(indifferent to the possibility to have more simultaneous connections, 
it can surely be useful, but I wouldn't put it on the top of the todo list).

> Disable Password Storing
>   An option to not use stored passwords seems to be the best easiest
>   alternative to implement.  I do not mind entering the profile password
>   for each connection.
> 
>   I tried leaving the profile password blank to see if DA would prompt me
>   for the password.  However, it does not.  It gives an "Access denied"
>   error message.
> 

I think this would be good the best. It shall be easy to implement, and is 
perfect for both who would like DA to remember his password and who would
not. You shall trust root anyway, but it may be useful not to have the 
password stored in a file, in some cases.

Bye,

Guido



-------------------------------------------------------
This SF.Net email is sponsored by: INetU
Attention Web Developers & Consultants: Become An INetU Hosting Partner.
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission!
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.