Updating Consumer replica fails referralto the master from the console.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> Date: Mon, 2 Feb 2009 13:26:18 -0800
> From: "Chavez, James R."<james.chavez at sanmina-sci.com>

> Hi Rich,
> Thank you for your previous response..The answer was actually embedded
> within your statement I believe.
>
> "This is a problem in general with some older clients that do not know
> how to properly follow LDAPv3 referrals"
>
> I used the mozldap ldapmodify tool and it worked to update entries that
> I point at the consumer.  I would have never guessed the openldap tool
> would not follow LDAPv3 referrals. Maybe a switch I missed or something.
> Thanks again for your suggestion.

The automatic referral chasing code in OpenLDAP's command line tools was 
deprecated years ago. It's a security vulnerability: most of the time it will 
hand your username and plaintext password to any arbitrary server without any 
warning.

Referrals are a gross flaw in the design of LDAP and should not be used. 
Distributed servers should use chaining to hide this detail from clients. 
Clients are not in any position to know whether or to what degree to trust the 
referred server, or what authentication domain or credentials are relevant on 
the referred server. Only the server admin knows these details; putting these 
decisions at the client is wrong.

-- 
   -- Howard Chu
   CTO, Symas Corp.           http://www.symas.com
   Director, Highland Sun     http://highlandsun.com/hyc/
   Chief Architect, OpenLDAP  http://www.openldap.org/project/




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux