-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Benjamin Smee wrote: > The typical way, perhaps, but its fairly insecure imo, I don't like > giving out more information then I have to and exposing my DIT to anon > binds is something that I dislike. Of course proper layout of the DIT > means that there is nothing sensitive being exposed, but I still don't > like giving out ANY information to anon users. My level of paranoia is > not always appropriate for others though :)
Allowing userPassword for auth means they can't read the attribute's value, but apply authentication to it. So, you are exposing no information. - -- Arturo "Buanzo" Busleiman - www.buanzo.com.ar Consultor en Seguridad Informatica President, Open Information System Security Group - Argentina -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFC5nB+AlpOsGhXcE0RAhL9AJ416fGcHhWerJwBwb4sJ3/788/2KQCff95f 5NCuJIagpDQmUYQoP9bktmI= =t8cs -----END PGP SIGNATURE----- -- [email protected] mailing list
