Re: [Freeipa-users] MinSSF suggestions?

2014-08-14 Thread Erinn Looney-Triggs
On Wednesday, August 13, 2014 08:57:19 PM Rob Crittenden wrote: > Erinn Looney-Triggs wrote: > > On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: > >> On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: > >>> -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 > >>> > >>> On 08/11/2014 09:08 AM, Martin Ko

Re: [Freeipa-users] MinSSF suggestions?

2014-08-13 Thread Rob Crittenden
Erinn Looney-Triggs wrote: > On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: >> On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: >>> -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 >>> >>> On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: > On Mon, Aug

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 12:33 PM, Alexander Bokovoy wrote: > On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: I guess the part I don't get here, is that this setting does not disable anonymous access to rootdse it just requires, as far as I under

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Alexander Bokovoy
On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: I guess the part I don't get here, is that this setting does not disable anonymous access to rootdse it just requires, as far as I understand, that TLS or some security be used for the connection. I currently have minssf set to 56 and am able to an

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: > On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 >> >> On 08/11/2014 09:08 AM, Martin Kosek wrote: >>> On 08/11/2014 04:24 PM, Jakub Hrozek wrote: >

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: > On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 >> >> On 08/11/2014 09:08 AM, Martin Kosek wrote: >>> On 08/11/2014 04:24 PM, Jakub Hrozek wrote: >

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Alexander Bokovoy
On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: On Sat, 09 Aug 2014, Erinn Looney-Triggs w

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: > On 08/11/2014 04:24 PM, Jakub Hrozek wrote: >> On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy >> wrote: >>> On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE-

Re: [Freeipa-users] MinSSF suggestions?

2014-08-11 Thread Martin Kosek
On 08/11/2014 04:24 PM, Jakub Hrozek wrote: > On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: >> On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: >>> -BEGIN PGP SIGNED MESSAGE- >>> Hash: SHA256 >>> >>> It would seem to be prudent to set the minssf setting for 389 to 56, >>

Re: [Freeipa-users] MinSSF suggestions?

2014-08-11 Thread Jakub Hrozek
On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: > On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: > >-BEGIN PGP SIGNED MESSAGE- > >Hash: SHA256 > > > >It would seem to be prudent to set the minssf setting for 389 to 56, > >however I am wondering why this isn't done by def

Re: [Freeipa-users] MinSSF suggestions?

2014-08-11 Thread Alexander Bokovoy
On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It would seem to be prudent to set the minssf setting for 389 to 56, however I am wondering why this isn't done by default, and if there is any reason why I shouldn't do it? Anonymous connection to L

[Freeipa-users] MinSSF suggestions?

2014-08-09 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It would seem to be prudent to set the minssf setting for 389 to 56, however I am wondering why this isn't done by default, and if there is any reason why I shouldn't do it? Thanks, - -Erinn -BEGIN PGP SIGNATURE- Version: GnuPG v1 iQEcBAEBC