-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Benjamin Smee wrote:
> The typical way, perhaps, but its fairly insecure imo, I don't like
> giving out more information then I have to and exposing my DIT to anon
> binds is something that I dislike. Of course proper layout of the DIT
> means that there is nothing sensitive being exposed, but I still don't
> like giving out ANY information to anon users. My level of paranoia is
> not always appropriate for others though :)

Allowing userPassword for auth means they can't read the attribute's value, but 
apply authentication
to it. So, you are exposing no information.

- --
Arturo "Buanzo" Busleiman - www.buanzo.com.ar
Consultor en Seguridad Informatica
President, Open Information System Security Group - Argentina
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFC5nB+AlpOsGhXcE0RAhL9AJ416fGcHhWerJwBwb4sJ3/788/2KQCff95f
5NCuJIagpDQmUYQoP9bktmI=
=t8cs
-----END PGP SIGNATURE-----
-- 
[email protected] mailing list

Reply via email to