oss-sec mailing list archives

Portus, missing LDAP server authentication


From: Raphael Geissert <atomo64 () gmail com>
Date: Sun, 17 Dec 2017 14:36:42 +0100

Hi,

Portus 2.2 and older provides LDAP integration for authenticating the
users. However, in spite of it providing advice on configuring it to
"to setup LDAP over SSL/TLS"[1], the implementation does not verify
the server's identity at all.

I'm writing about it here mainly because there appears to be some
intention of TLS support. Users might expect it to actually provide
some kind of security.

Interestingly enough, the documentation and the config file comments
say  'the recommended [method] is "starttls".'[2] I don't know where
they got that from.

CC'ing SUSE's security team.

I have not yet reported it to the portus team directly, nor requested
a CVE id (though I'm tempted to request one, to err on the side of
safety).


[1]http://port.us.org/docs/Configuring-Portus.html
[2]https://github.com/SUSE/Portus/blob/master/config/config.yml#L49

Cheers,
-- 
Raphael Geissert


Current thread: