Re: [SECURITY] [DSA 2096-1] New zope-ldapuserfolder packages fix authentication bypass

2010-08-29 Thread Arsi Hartikainen
On 24.8.2010, at 23.54, Sebastien Delafond wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > - > Debian Security Advisory DSA-2096-1 secur...@debian.org > http://www.debian.org/security/

Re: Upcoming lenny point release

2010-08-29 Thread Russ Allbery
Vitaly writes: > Are there any plans to reduce this shameful list?: > http://bugs.debian.org/release-critical/other/stable.html Many of the open RC bugs against stable are artifacts of mistakes made in closing the bug, and many of those have been resolved. You'll find that this list is much sho

Re: About how to protect network resources in LDAP environment?

2010-08-29 Thread Russ Allbery
"Boyd Stephen Smith Jr." writes: > On Saturday, August 28, 2010 20:29:50 you wrote: >> Can't root just read/steal and even use sockets/fifos/pipes owned by >> all other users? Any Kerberos credentials used on the local system >> would also be usable by root. Correct. > From what I understand,

Michael Baumgartner/bam/SFS ist außer Haus.

2010-08-29 Thread Michael Baumgartner
Ich werde ab 28.08.2010 nicht im Büro sein. Ich kehre zurück am 13.09.2010. Ich werde Ihre Nachricht nach meiner Rückkehr beantworten. In dringenden Fällen wenden Sie sich an Markus Spirig m...@sfsintec.biz

re:Upcoming lenny point release

2010-08-29 Thread Vitaly
Are there any plans to reduce this shameful list?: http://bugs.debian.org/release-critical/other/stable.html -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/e1opgaa

Re: About how to protect network resources in LDAP environment?

2010-08-29 Thread Boyd Stephen Smith Jr.
On Saturday, August 28, 2010 20:29:50 you wrote: >On Sat, Aug 28, 2010 at 3:08 AM, Boyd Stephen Smith Jr. > wrote: >> In <4c77f5ca.6030...@gmail.com>, Min Wang wrote: >>>(1) does this approach >>> >>>prevent user1-> root ( su-> ) user2? >>> >> Yes. "su" does not grant Kerberos credentials. > >Can't

Re: About how to protect network resources in LDAP environment?

2010-08-29 Thread Bernhard R. Link
* Mike Mestnik [100829 03:30]: > >>thanks.  I'm totally a newbie to this nfs4/gssapi/kerberos. > >> > >>(1) does this approach > >> > >>prevent user1-> root ( su-> ) user2? > > > > Yes. "su" does not grant Kerberos credentials. > > > Can't root just read/steal and even use sockets/fifos/pipes owne