Re: OpenLDAP
Tim Holloway <timh-kiPKLF+HnOy1Z/[email protected]> Sat, 18 Aug 2012 19:05:10 -0400
| Newsgroups | gmane.org.user-groups.jaxlug |
|---|---|
| Message-ID | <[email protected]> |
The original question was not about identity management however, or even LDAP in general. It was about openLDAP and only openLDAP. A "one-size-fits-all" approach to security is in itself a security risk. One of the reasons that Windows shops generally stink at security is because the Windows Way is to use a "do-everything" system combined with a "monkey-at-the-keyboard" control interface. The problem is that when you have something this complex fronted with a simplistic interface, the PHBs appoint the closest thing they can get to an actual monkey and no security system is going to help if the person controlling it doesn't understand what's going on under the covers. For example, I've never been able to justify bringing up Kerberos on the Mousetech LAN, because an SSO solution is not a good fit for how things are done here. So a system that runs Kerberos for me would be at best a waste and at worst, consume resources I could employ better elsewhere. On the other hand, I repel hundreds of attempts to attack Apache proxies each day, just wound down from 48 hours of repelling DNS reflection attacks - which, having an authoritative nameserver - cannot be simply firewalled, and that's not even mentioning the various HTTP-based exploits I bounce routinely. And then, of course, there's spam. I don't even accept connections from the ".ko" or ".ru" domains, since before I moved to a more powerful mailserver, I was being DDOS'ed by spam from those countries alone. I have whitelists, blacklists, Bayesian filters and a set of procmail rules you wouldn't believe for things like email from ".uk" spammed by "Vision Space Marketing", which isn't even based in the UK, or so it claims. So I'm serious about security. But I was serious many years before Red Hat IPA came along, and in fact, I have production hardware that cannot accomodate CentOS 6 but is still good enough (and secure enough) for older software. In fact, one reason I'm not rushing to CentOS 6 is that certain resources that are critical to daily operation have not been carried forward to that platform. Tim On Sat, 2012-08-18 at 15:20 -0700, Kristian Erik Hermansen wrote: > On Fri, Aug 17, 2012 at 6:08 PM, Tim Holloway <timh-kiPKLF+HnOy1Z/[email protected]> wrote: > > I think that might be a bit of overkill. Red Hat's IPA uses LDAP as a > > datastore, but it's LDAP+Kerberos++. Not only that, but it uses an > > extended LDAP schema. So if you're just trying to get started with > > OpenLDAP experiments instead fo raising an entire enterprise identity > > and security infrastructure at one go, definitely way more than that. > > And actually, Red Hat bought Novell's LDAP server product several years > > ago, and so be using that instead of OpenLDAP for IPA. > > It's only "overkill" if you don't actually take the security of all > your systems seriously... > > https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Linux/6/html-single/Identity_Management_Guide/index.html --------------------------------------------------------------------- Archive http://marc.info/?l=jaxlug-list&r=1&w=2 RSS Feed http://www.mail-archive.com/[email protected]/maillist.xml Unsubscribe [email protected]