Re: OpenLDAP

Tim Holloway <timh-kiPKLF+HnOy1Z/[email protected]> Sat, 18 Aug 2012 19:05:10 -0400
Newsgroups gmane.org.user-groups.jaxlug
Message-ID <[email protected]>
The original question was not about identity management however, or even
LDAP in general. It was about openLDAP and only openLDAP.

A "one-size-fits-all" approach to security is in itself a security risk.
One of the reasons that Windows shops generally stink at security is
because the Windows Way is to use a "do-everything" system combined with
a "monkey-at-the-keyboard" control interface. The problem is that when
you have something this complex fronted with a simplistic interface, the
PHBs appoint the closest thing they can get to an actual monkey and no
security system is going to help if the person controlling it doesn't
understand what's going on under the covers.

For example, I've never been able to justify bringing up Kerberos on the
Mousetech LAN, because an SSO solution is not a good fit for how things
are done here. So a system that runs Kerberos for me would be at best a
waste and at worst, consume resources I could employ better elsewhere.

On the other hand, I repel hundreds of attempts to attack Apache proxies
each day, just wound down from 48 hours of repelling DNS reflection
attacks - which, having an authoritative nameserver - cannot be simply
firewalled, and that's not even mentioning the various HTTP-based
exploits I bounce routinely.

And then, of course, there's spam. I don't even accept connections from
the ".ko" or ".ru" domains, since before I moved to a more powerful
mailserver, I was being DDOS'ed by spam from those countries alone. I
have whitelists, blacklists, Bayesian filters and a set of procmail
rules you wouldn't believe for things like email from ".uk" spammed by
"Vision Space Marketing", which isn't even based in the UK, or so it
claims.

So I'm serious about security. But I was serious many years before Red
Hat IPA came along, and in fact, I have production hardware that cannot
accomodate CentOS 6 but is still good enough (and secure enough) for
older software. In fact, one reason I'm not rushing to CentOS 6 is that
certain resources that are critical to daily operation have not been
carried forward to that platform.

   Tim

On Sat, 2012-08-18 at 15:20 -0700, Kristian Erik Hermansen wrote:
> On Fri, Aug 17, 2012 at 6:08 PM, Tim Holloway <timh-kiPKLF+HnOy1Z/[email protected]> wrote:
> > I think that might be a bit of overkill. Red Hat's IPA uses LDAP as a
> > datastore, but it's LDAP+Kerberos++. Not only that, but it uses an
> > extended LDAP schema. So if you're just trying to get started with
> > OpenLDAP experiments instead fo raising an entire enterprise identity
> > and security infrastructure at one go, definitely way more than that.
> > And actually, Red Hat bought Novell's LDAP server product several years
> > ago, and so be using that instead of OpenLDAP for IPA.
> 
> It's only "overkill" if you don't actually take the security of all
> your systems seriously...
> 
> https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Linux/6/html-single/Identity_Management_Guide/index.html



---------------------------------------------------------------------
Archive      http://marc.info/?l=jaxlug-list&r=1&w=2
RSS Feed     http://www.mail-archive.com/[email protected]/maillist.xml
Unsubscribe  [email protected]