From: Mark Reynolds <mreynolds@xxxxxxxxxx>
Sent: Thursday, October 21, 2021 9:36 AM To: Michael Starling <mlstarling31@xxxxxxxxxxx>; General discussion list for the 389 Directory server project. <389-users@xxxxxxxxxxxxxxxxxxxxxxx> Subject: Re: [389-users] anonymous binds
On 10/21/21 9:26 AM, Michael Starling wrote:
It depends on how the client is performing the authentication. If it's searching for a single user, then you will be fine. Since this is a "size limit" that means it will not "send" more than 2000 entries back to the client. However, size limit does not impact how far into the database a search can go. If you know SSSD is hitting the sizelimit then yes it is absolutely possible that it will not find the entry and cause authentication to unexpectedly fail.
Ideally you should create a "bind user" that has the correct access you need. Opening up anonymous access is not ideal or recommended.
Regards,
Thank you.
-- Directory Server Development Team |
_______________________________________________ 389-users mailing list -- 389-users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to 389-users-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/389-users@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure