lists.arthurdejong.org
RSS feed

[nssldap] release 0.6.8 of nss-ldapd

[Date Prev][Date Next] [Thread Prev][Thread Next]

[nssldap] release 0.6.8 of nss-ldapd



A new release of nss-ldapd was made which addresses a potential security
problem. This release is available from:
  http://ch.tudelft.nl/~arthur/nss-ldapd/

The problem is that the nss-ldapd.conf can be installed world readable.
If the file contains a bindpw option having the file world readable
exposes that information. Users are advised to check the permissions of
the file. Some warning messages have been added to both the sample
configuration file and the manual page.

This release also includes improvements to the SSL options, disables
reading of general LDAP configuration files, is more lenient with user
names and has a fix for Solaris.

For more information and changes in this release, please see the URL
above. Any feedback is greatly appreciated. Thanks for all the feedback
already provided.

-- 
-- arthur - arthur@ch.tudelft.nl - http://ch.tudelft.nl/~arthur --