Files
freeipa/ipaserver/install
Martin Kosek df13cdcb97 Forbid public access to DNS tree
With a publicly accessible DNS tree in LDAP, anyone with an access
to the LDAP server can get all DNS data as with a zone transfer
which is already restricted with ACL. Making DNS tree not readable
to public is a common security practice and should be applied
in FreeIPA as well.

This patch adds a new deny rule to forbid access to DNS tree to
users or hosts without an appropriate permission or users which
are not members of admins group. The new permission/aci is
applied both for new installs and upgraded servers.

bind-dyndb-ldap plugin is allowed to read DNS tree without any
change because its principal is already a member of "DNS
Servers" privilege.

https://fedorahosted.org/freeipa/ticket/2569
2012-04-01 21:17:04 -04:00
..
2012-04-01 21:17:04 -04:00
2010-12-20 17:19:53 -05:00
2011-12-06 08:29:53 -05:00
2012-04-01 16:54:55 -04:00
2011-09-14 18:45:13 -04:00
2012-02-09 13:20:28 -06:00
2012-02-16 14:43:08 +01:00