Re:Certificate authentication with SASL External

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> From: Rob Crittenden <rcritten at redhat.com>
>
> Yann wrote:
>   
>> Thanks Richard,
>>
>> but this howto explain how to to match DN certificate to LDAP entry... my
>> problem is; i don't want to have a corresponding entry in LDAP directory...
>>
>> I want to be identify only by the DN in the certificate, and match some ACL..
>> that all. No need to have an entry in the LDAP.
>>
>> If it's possible in DS...
>>     
>
> So you want to bind to the directory server with a valid client 
> certificate for a user that doesn't exist? For what purpose?
>   

There is no reason to assume any connection between SASL identities and 
LDAP directory entries. Moreover, in a true distributed directory 
system, there's no reason to assume that an entry for a valid user is 
present on every DSA in the system. Of course, the folks who developed 
LDAP didn't understand this essential bit of X.500, so it's no surprise 
that you're unfamiliar with distributed authentication. Remember that 
authentication is not the same as authorization - having the valid 
certificate just proves who you are to the server; the server doesn't 
have to accord you any privileges/authorization just because of that.

-- 
  -- Howard Chu
  Chief Architect, Symas Corp.  http://www.symas.com
  Director, Highland Sun        http://highlandsun.com/hyc
  OpenLDAP Core Team            http://www.openldap.org/project/




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux