Re: [Bacula-users] authorization security

2005-10-25 Thread Russell Howe
Kern Sibbald wrote: > The idea was that if an Address is specified that Bacula would then *require* > that the Director that is calling is at the specified address. This is sort > of a simple minded libwrap feature. Another way would be for Bacula to support Kerberos, which would be lovely, b

Re: [Bacula-users] authorization security

2005-10-25 Thread Kern Sibbald
On Friday 21 October 2005 19:38, Phil Stracchino wrote: > Viktorija wrote: > > what about Windows type client? I don't need administrator rights for > > stolling such file :) Actually, Viktorija, using some clever insight, has brought up an interesting problem. If you have a brain-damaged machin

Re: [Bacula-users] authorization security

2005-10-21 Thread Phil Stracchino
Viktorija wrote: > what about Windows type client? I don't need administrator rights for > stolling such file :) But you're using restricted consoles on your Windows clients that allow access only to jobs saved for that machine, right? Or maybe you don't even HAVE a console installed on the

Re: [Bacula-users] authorization security

2005-10-21 Thread Dan Langille
On 21 Oct 2005 at 19:04, Viktorija wrote: > yes. but as i said before i can see this password in stolen > bacula-fd.conf file and i can use it for configuring bacula server to > stole other needed files from that server without having > administrators rights. So it doesn't is password in plain tex

Re: [Bacula-users] authorization security

2005-10-21 Thread Viktorija
yes. but as i said before i can see this password in stolen bacula-fd.conf file and i can use it for configuring bacula server to stole other needed files from that server without having administrators rights. So it doesn't is password in plain text or CRAM-MD5. I think it would be great if bac

Re: [Bacula-users] authorization security

2005-10-21 Thread Viktorija
what about Windows type client? I don't need administrator rights for stolling such file :) As i understand correctly stunnel supports encrypted tunnel for data transfering not authorization, but i need _safe_ authorization. Also such encryption will ask more time for backuping but i have about

Re: [Bacula-users] authorization security

2005-10-21 Thread Steve Greenland
On Fri, Oct 21, 2005 at 07:04:57PM +0300, Viktorija wrote: > > But for now i am searching how to avoid situations with stolen passwords. Don't allow your passwords to be stolen. You haven't explained how someone can read a properly protected bacula-fd.conf but NOT arbitrary other files on the sy

Re: [Bacula-users] authorization security

2005-10-21 Thread Steve Greenland
On Fri, Oct 21, 2005 at 05:42:18PM +0300, Viktorija wrote: > i have some questions about authorization from client (bacula-fd) to > server (bacula-dir). How about security? Maybe somebody can describe > very detailed authorization process client-server-client to me? What > if i have stolen bacula-

Re: [Bacula-users] authorization security

2005-10-21 Thread Dan Langille
On 21 Oct 2005 at 18:30, Viktorija wrote: > Also i still want to know details about authorization > client-server-client :) Thanks! >From http://www.bacula.org/dev-manual/Current_State_Bacula.html CRAM-MD5 password authentication between each component (daemon). The daemons authenticate using

[Bacula-users] authorization security

2005-10-21 Thread Viktorija
Hello, i have some questions about authorization from client (bacula-fd) to server (bacula-dir). How about security? Maybe somebody can describe very detailed authorization process client-server-client to me? What if i have stolen bacula-fd.conf where is Director password and other information.