[Freeipa-users] FreeIPA Security issue : Anonymous user can fetch user details from IPA without authenticating

Will Sheldon mail at willsheldon.com
Fri Jan 3 17:50:04 UTC 2014


Thanks Petr, that certainly makes sense from the point of view of
functionality.

I do think the default is sane, but there are a lot of possible deployment
scenarios and my concern is that a junior or time poor admin looking to
implement a trusted, secure solution should be made aware of any potential
data leakage during configuration, (preferably in big red letters in the
documentation, or better still, the install script).

Though I am reluctant to draw comparisons between IPA and MS AD they do
seem inevitable. AD restricts anonymous binds to the rootDSE entry by
default and as such this may be considered by many to be the expected
default. Extra care should therefore be made to point out this difference.
To do otherwise risks undermining the confidence of users in the security
of the solution.



On Fri, Jan 3, 2014 at 4:53 AM, Petr Viktorin <pviktori at redhat.com> wrote:

> On 01/03/2014 02:23 AM, Will Sheldon wrote:
>
>>
>> This is cause for concern. Is there a hardening / best practices for
>> production guide anywhere, did I miss a section of the documentation?
>>
>> What else do I need to secure?
>>
>> I understand that there is a tradeoff between security and
>> compatibility, but maybe there should be a ipa-secure script somewhere?
>>
>
> We are working on making the read permissions granular, so you can make
> your own tradeoffs if IPA defaults aren't appropriate for your use.
>
> The work is tracked in https://fedorahosted.org/freeipa/ticket/3566 and
> linked tickets 4032-4034.
>
>  On Wed, Jan 1, 2014 at 10:41 AM, Jitse Klomp <jitseklomp at gmail.com
>> <mailto:jitseklomp at gmail.com>> wrote:
>>
>>     It is possible to disable anonymous binds to the directory server.
>>     Take a look at
>>     https://docs.fedoraproject.__org/en-US/Fedora/18/html/__
>> FreeIPA_Guide/disabling-anon-__binds.html
>>
>>     <https://docs.fedoraproject.org/en-US/Fedora/18/html/
>> FreeIPA_Guide/disabling-anon-binds.html>
>>
>>       - Jitse
>>
>>
>>
>>     On 01/01/2014 07:01 PM, Rajnesh Kumar Siwal wrote:
>>
>>         It exposes the details of all the users/admins in the environment.
>>         There should be a user that the IPA should use to fetch the
>>         details from
>>         the IPA Servers. Without Authentication , no one should be able
>>         to fetch
>>         any information from the IPA Server.
>>
>
>
> --
> Petr³
>
>
> _______________________________________________
> Freeipa-users mailing list
> Freeipa-users at redhat.com
> https://www.redhat.com/mailman/listinfo/freeipa-users
>



-- 

Kind regards,

Will Sheldon
+1.(778)-689-4144
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20140103/d985e6a5/attachment.htm>


More information about the Freeipa-users mailing list