[Freeipa-devel] Visibility of the sensitive LDAP data

2011-06-08 Thread Dmitri Pal
Hi, We have been through this some time before and the decision made then still left me uneasy. We said that LDAP is by nature something is a readable by an authenticated used. Other than special password and key related attributes everything else should be readable. Now we have a bug

Re: [Freeipa-devel] Visibility of the sensitive LDAP data

2011-06-08 Thread Simo Sorce
On Wed, 2011-06-08 at 14:15 -0400, Dmitri Pal wrote: Hi, We have been through this some time before and the decision made then still left me uneasy. We said that LDAP is by nature something is a readable by an authenticated used. Other than special password and key related attributes

Re: [Freeipa-devel] Visibility of the sensitive LDAP data

2011-06-08 Thread JR Aquino
On Jun 8, 2011, at 11:30 AM, Simo Sorce wrote: On Wed, 2011-06-08 at 14:15 -0400, Dmitri Pal wrote: Hi, We have been through this some time before and the decision made then still left me uneasy. We said that LDAP is by nature something is a readable by an authenticated used. Other than

Re: [Freeipa-devel] Visibility of the sensitive LDAP data

2011-06-08 Thread JR Aquino
On Jun 8, 2011, at 12:29 PM, Dmitri Pal wrote: On 06/08/2011 03:15 PM, JR Aquino wrote: 1) Leave as is and not bother at all (i.e. it is what it is) 2) Leave as is and defer the solution till later (do not fix it in 2.1 defer to 2.2) 3) Leave as is but document how to do it