LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-22-2006, 10:35 AM   #1
Neruocomp
Member
 
Registered: Oct 2004
Distribution: Slackware, CentOS
Posts: 135

Rep: Reputation: 15
Ldap security question


I'm currently trying to setup samba as a primary domain controller using ldap, but to do so, I need an account in ldap with uid = 0, so that I can add machines to the domain. Otherwise it fails with access denied.

My boss is worried that if someone hacks our ldap server, they can get at all of our machines using that account. Is it really that much of a concern? Or is there a work around?
 
Old 05-22-2006, 11:21 AM   #2
musicman_ace
Senior Member
 
Registered: May 2001
Location: Indiana
Distribution: Gentoo, Debian, RHEL, Slack
Posts: 1,555

Rep: Reputation: 46
I'd wonder how insecure a network would be to able to be comprimised in that way. The 'admin' or 'root' account (UID=0) shouldn't be allowed to login remotely on any system. If its linux based then use su, if its windows then use runas. I'd hope that there are firewalls in place and restrictions on internal and external port traffic.

Keep any ldap directory service patched since it is critical. Audit the hell out of it, and watch the logs. How is your ldap traffic being submitted on your network? Is it secure?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Authenticating Against Active Directory LDAP Question pyotr1 Linux - General 2 09-30-2006 06:25 PM
LDAP! basic question itz2000 Linux - General 6 11-06-2005 10:19 AM
Postfix and LDAP - Virtual User Question mephitic Linux - Software 0 10-04-2005 09:27 AM
Short question PHP + LDAP Hko Programming 2 08-07-2004 10:04 AM
LDAP question dominant Linux - General 3 03-30-2004 09:22 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration