[Freeipa-users] FreeIPA Security issue : Anonymous user can fetch user details from IPA without authenticating

Jitse Klomp jitseklomp at gmail.com
Wed Jan 1 18:41:58 UTC 2014


It is possible to disable anonymous binds to the directory server. Take 
a look at 
https://docs.fedoraproject.org/en-US/Fedora/18/html/FreeIPA_Guide/disabling-anon-binds.html

  - Jitse


On 01/01/2014 07:01 PM, Rajnesh Kumar Siwal wrote:
> It exposes the details of all the users/admins in the environment.
> There should be a user that the IPA should use to fetch the details from
> the IPA Servers. Without Authentication , no one should be able to fetch
> any information from the IPA Server.




More information about the Freeipa-users mailing list