Re: Could sudo be an security issue?

2003-05-16 Thread Torbjorn Pettersson
Phillip Hofmeister <[EMAIL PROTECTED]> writes: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On Thu, 15 May 2003 at 02:31:22PM +0200, Torbjorn Pettersson wrote: > > Compare this with a secure, locked down root password in a > > sealed letter in a safe somew

Re: Could sudo be an security issue?

2003-05-15 Thread Torbjorn Pettersson
Stewart James <[EMAIL PROTECTED]> writes: > Hi all, > > My manager just came in asking questions about sudo. We use sudo here as a > replacement for hacing to know root passwords - in general there are > around 5 of us who need root access to the machines we maintain. we > typically have just fal

Re: VPN: SSH or IPSec???

2003-04-18 Thread Torbjorn Pettersson
Vineet Kumar <[EMAIL PROTECTED]> writes: > --4Ckj6UjgE2iN1+kY > Content-Type: text/plain; charset=us-ascii > Content-Disposition: inline > Content-Transfer-Encoding: quoted-printable > > * Anne Carasik ([EMAIL PROTECTED]) [030416 10:58]: > > A true VPN is something like IPSec. SSH and SSL only tu

Re: Security issues with the PAM modules for Kerberos?

2002-02-14 Thread Torbjorn Pettersson
Arne Nordmark <[EMAIL PROTECTED]> writes: > Hello, > > In the description for libpam-heimdal it says: "This module should only > be used for local logins unless you really know what you are doing". On > the other hand it is quite tempting to use it for IMAP servers etc, so > what are the issues?

Re: Security issues with the PAM modules for Kerberos?

2002-02-14 Thread Torbjorn Pettersson
Arne Nordmark <[EMAIL PROTECTED]> writes: > Hello, > > In the description for libpam-heimdal it says: "This module should only > be used for local logins unless you really know what you are doing". On > the other hand it is quite tempting to use it for IMAP servers etc, so > what are the issues?