码迷,mamicode.com
首页 > 其他好文 > 详细

ldap--密码获取修复

时间:2020-10-08 18:38:11      阅读:24      评论:0      收藏:0      [点我收藏+]

标签:文档   btree   read   conf   user   password   ever   sel   amp   

官网文档:
https://www.freebsd.org/doc/en_US.ISO8859-1/articles/ldap-auth/secure.html

4.1. Setting Attributes Read-only
Several attributes in LDAP should be read-only. If left writable by the user, for example, a user could change his uidNumber attribute to 0 and get root access!

To begin with, the userPassword attribute should not be world-readable. By default, anyone who can connect to the LDAP server can read this attribute. To disable this, put the following in slapd.conf:

Example 8. Hide Passwords
access to dn.subtree="ou=people,dc=example,dc=org"
attrs=userPassword
by self write
by anonymous auth
by * none

access to
by self write
by
read

ldap--密码获取修复

标签:文档   btree   read   conf   user   password   ever   sel   amp   

原文地址:https://blog.51cto.com/13420391/2540309

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!