OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Re[3]: [suse-security] NSCD
From: Roman Drahtmueller (drahtsuse.de)
Date: Wed Dec 27 2000 - 06:03:56 CST


Hi Andreas,

>
> Hmm, that still doesn't fix all the nasty other effects with UIDs.
> At my previous employer (a German Linux company) I used to disable NSCD on all
> systems I ever configured. My colleagues did or still do the same (Hi MGE!).
> So far it only made sense to enable nscd on systems with network
> authentication (NIS, LDAP).

Right, I remember! There was something else: If you have two users with
the same numerical userid, the nscd would gratefully return the second one
instead of the first one. This happens because the cache is built that
way. It may even have security implications...

> cheers
> afx

Take care and have a happy new year!
Roman.

-- 
 -                                                                    -
| Roman Drahtmüller <drahtsuse.de>     "Caution: Cape does not        |
  SuSE GmbH - Security                  enable user to fly."
| Nürnberg, Germany                     (Batman Costume warning label) |
 -                                                                    -

--------------------------------------------------------------------- To unsubscribe, e-mail: suse-security-unsubscribesuse.com For additional commands, e-mail: suse-security-helpsuse.com