oss-sec mailing list archives
Portus, missing LDAP server authentication
From: Raphael Geissert <atomo64 () gmail com>
Date: Sun, 17 Dec 2017 14:36:42 +0100
Hi, Portus 2.2 and older provides LDAP integration for authenticating the users. However, in spite of it providing advice on configuring it to "to setup LDAP over SSL/TLS"[1], the implementation does not verify the server's identity at all. I'm writing about it here mainly because there appears to be some intention of TLS support. Users might expect it to actually provide some kind of security. Interestingly enough, the documentation and the config file comments say 'the recommended [method] is "starttls".'[2] I don't know where they got that from. CC'ing SUSE's security team. I have not yet reported it to the portus team directly, nor requested a CVE id (though I'm tempted to request one, to err on the side of safety). [1]http://port.us.org/docs/Configuring-Portus.html [2]https://github.com/SUSE/Portus/blob/master/config/config.yml#L49 Cheers, -- Raphael Geissert
Current thread:
- Portus, missing LDAP server authentication Raphael Geissert (Dec 17)
- Re: Portus, missing LDAP server authentication Kiall Mac Innes (Dec 17)
- Re: Portus, missing LDAP server authentication Marcus Meissner (Dec 17)