diff options
Diffstat (limited to 'zarb-ml/mageia-sysadm/2010-November/000950.html')
-rw-r--r-- | zarb-ml/mageia-sysadm/2010-November/000950.html | 84 |
1 files changed, 84 insertions, 0 deletions
diff --git a/zarb-ml/mageia-sysadm/2010-November/000950.html b/zarb-ml/mageia-sysadm/2010-November/000950.html new file mode 100644 index 000000000..4d2551c76 --- /dev/null +++ b/zarb-ml/mageia-sysadm/2010-November/000950.html @@ -0,0 +1,84 @@ +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> +<HTML> + <HEAD> + <TITLE> [Mageia-sysadm] [LONG] sympa ( and web apps ) ldap authentication + </TITLE> + <LINK REL="Index" HREF="index.html" > + <LINK REL="made" HREF="mailto:mageia-sysadm%40mageia.org?Subject=Re%3A%20%5BMageia-sysadm%5D%20%5BLONG%5D%20sympa%20%28%20and%20web%20apps%20%29%0A%09ldap%09authentication&In-Reply-To=%3C20101125214049.GU21938%40mars-attacks.org%3E"> + <META NAME="robots" CONTENT="index,nofollow"> + <META http-equiv="Content-Type" content="text/html; charset=us-ascii"> + <LINK REL="Previous" HREF="000949.html"> + <LINK REL="Next" HREF="000963.html"> + </HEAD> + <BODY BGCOLOR="#ffffff"> + <H1>[Mageia-sysadm] [LONG] sympa ( and web apps ) ldap authentication</H1> + <B>nicolas vigier</B> + <A HREF="mailto:mageia-sysadm%40mageia.org?Subject=Re%3A%20%5BMageia-sysadm%5D%20%5BLONG%5D%20sympa%20%28%20and%20web%20apps%20%29%0A%09ldap%09authentication&In-Reply-To=%3C20101125214049.GU21938%40mars-attacks.org%3E" + TITLE="[Mageia-sysadm] [LONG] sympa ( and web apps ) ldap authentication">boklm at mars-attacks.org + </A><BR> + <I>Thu Nov 25 22:40:49 CET 2010</I> + <P><UL> + <LI>Previous message: <A HREF="000949.html">[Mageia-sysadm] [LONG] sympa ( and web apps ) ldap authentication +</A></li> + <LI>Next message: <A HREF="000963.html">[Mageia-sysadm] [LONG] sympa ( and web apps ) ldap authentication +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#950">[ date ]</a> + <a href="thread.html#950">[ thread ]</a> + <a href="subject.html#950">[ subject ]</a> + <a href="author.html#950">[ author ]</a> + </LI> + </UL> + <HR> +<!--beginarticle--> +<PRE>On Thu, 25 Nov 2010, Michael Scherer wrote: + +><i> > > - using email as login is dangerous. Since the email is freely editable +</I>><i> > > in catdap ( and multivalued ), someone could perfectly change his email +</I>><i> > > after opening a account, and thus get access to sympa subscription of +</I>><i> > > someone else. +</I>><i> > +</I>><i> > And lose their account to the user whose email address was used as soon as we +</I>><i> > allow user-initiated password reset ... +</I>><i> +</I>><i> Which is not a problem, since opening a account is free. If we start to +</I>><i> have some private mls ( such as the one requested for forums ), reading +</I>><i> archive would be a privacy issue, and so step must be taken to prevent +</I>><i> that. +</I>><i> +</I>><i> But my main point is not this particular example who is quite easy to +</I>><i> prevent. But rather that letting people freely edit the attribute they +</I>><i> use for login is IMHO a risky operation given the wide range of +</I>><i> application that we will have. +</I>><i> +</I>><i> Editing by admin should be ok. +</I> +To avoid this, I think email should not be freely editable in catdat, +but should be verified first before being actually changed in ldap. +When changing email, the user should receive on the new email an URL +to open to confirm he is the owner of the email. + +</PRE> + + + +<!--endarticle--> + <HR> + <P><UL> + <!--threads--> + <LI>Previous message: <A HREF="000949.html">[Mageia-sysadm] [LONG] sympa ( and web apps ) ldap authentication +</A></li> + <LI>Next message: <A HREF="000963.html">[Mageia-sysadm] [LONG] sympa ( and web apps ) ldap authentication +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#950">[ date ]</a> + <a href="thread.html#950">[ thread ]</a> + <a href="subject.html#950">[ subject ]</a> + <a href="author.html#950">[ author ]</a> + </LI> + </UL> + +<hr> +<a href="https://www.mageia.org/mailman/listinfo/mageia-sysadm">More information about the Mageia-sysadm +mailing list</a><br> +</body></html> |