Andrea Barisani lcars at gentoo.org
Tue Jun 14 14:40:24 EDT 2005

On Tue, Jun 14, 2005 at 12:39:06PM -0600, Todd C. Miller wrote:
> In message <20050614181346.GT3960 at sole.infis.univ.trieste.it>
> 	so spake Andrea Barisani (lcars):
> > Yes that was my workaround and indeed it is documented in README.LDAP but I
> > think you should stress more about this problem security_wise, simply showing
> > that you can redefine the conf doesn't show the security aspect of this issue
> > . 
> > 
> > Also don't you think that making sudo+ldap rootdn aware could be a good
> > option? (/etc/ldap.secret mode 600)
> It doesn't look like adding rootbinddn should be hard.  Am I correct
> in believing sudo just needs to look for rootbinddn in ldap.conf
> and if found use the password stored in /etc/ldap.secret?

Yes, actually rootbinddn (which is used only by processes with UID=0) is a
pretty useless feature pam_ldap/nss_ldap-wise (since usually when using passwd+ldap 
we want to auth the user with its own password), but it sounds perfect for sudo.

