[Freeipa-users] FreeIPA Security issue : Anonymous user can fetch user details from IPA without authenticating

2014-01-01 Thread Rajnesh Kumar Siwal
Hi, IPA has really been a great Project. But, I was really concerned about the security of IPA I have been testing it on RHEL 7 Beta for some time. ldapsearch is able to fetch the details from the IPA Server without Authentication. I would appreciate if IPA team could work on securing the IPA

Re: [Freeipa-users] FreeIPA Security issue : Anonymous user can fetch user details from IPA without authenticating

2014-01-01 Thread Jitse Klomp
It is possible to disable anonymous binds to the directory server. Take a look at https://docs.fedoraproject.org/en-US/Fedora/18/html/FreeIPA_Guide/disabling-anon-binds.html - Jitse On 01/01/2014 07:01 PM, Rajnesh Kumar Siwal wrote: It exposes the details of all the users/admins in the

[Freeipa-users] AD - Freeipa trust confusion

2014-01-01 Thread Andrew Holway
Hello, I am attempting to set up trust between my test freeipa server at ipa.wibble.com. and my test AD server at win-5uglhak7rin.prattle.com. In the GUI I can see the following in Trusts ยป prattle.com. Realm name: prattle.com Domain NetBIOS name: PRATTLE Domain Security Identifier: