Re: Security hole?

Eric Sandall <[email protected]> Tue, 25 Jan 2005 08:24:50 -0800
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
Quoting Graham Leggett <[email protected]>:
<snip>
> If somebody gained access to the root account, they could gain access to
> the LDAP server database (if stored locally), or they could trojan the
> directory_administrator binary, or they could sniff the LDAP connection
> (if clear text) for the password, the password stored is the least of your
> problems.
>
> However software that stores passwords locally should warn the user that
> this is happening, and allow the user the option to not save the password
> locally if the user so chooses. Your concern is definitely valid - where
> an end user is not comfortable with saving passwords to disk, they should
> be given the option not to.
>
> Regards,
> Graham

So we'd just need an optional config in DA (perhaps disabled by default?) to
store the password locally (in ~/.directory_administrator).

-sandalle

--
Eric Sandall                     |  Source Mage GNU/Linux Developer
[email protected] PGP: 0xA8EFDD61  |  http://www.sourcemage.org/
http://eric.sandall.us/          |  SysAdmin @ Inst. Shock Physics @ WSU
http://counter.li.org/  #196285  |  http://www.shock.wsu.edu/

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl