Project

General

Profile

Actions

Bug #646

closed

restrict LDAP service accounts

Added by Marc Dequènes almost 5 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
Urgent
Category:
Service :: IS / AAA / PKI
Start date:
2019-04-21
Due date:
% Done:

100%

Estimated time:
Patch Available:
Confirmed:
No
Branch:
restrict_ldap_service_accounts_646
Entity:
DuckCorp
Security:
Yes
Help Needed:

Description

  • check if only necessary fields are readable
  • limit which IP can auth with these accounts
Actions #1

Updated by Marc Dequènes almost 5 years ago

  • Status changed from New to In Progress
  • Assignee set to Marc Dequènes
Actions #2

Updated by Marc Dequènes almost 5 years ago

  • % Done changed from 0 to 10
  • Branch set to restrict_ldap_service_accounts_646

Unfortunately LDAP IP restrictions do not understand CIDR notation, so I need to convert into <address>%<netmask>.

There is a bug with ipaddr('address') I need to report.

Actions #3

Updated by Marc Dequènes about 4 years ago

  • Status changed from In Progress to Resolved
  • % Done changed from 10 to 100

Pilou is kindly taking care of the Ansible bug; I just added a quick workaround.

Actions

Also available in: Atom PDF