oss-sec mailing list archives

Re: Portus, missing LDAP server authentication


From: Kiall Mac Innes <kiall () macinnes ie>
Date: Sun, 17 Dec 2017 15:20:58 -0500

FYI - I've forwarded this to some of the Portus developers.

-------- Original Message --------
On 17 Dec 2017, 14:36, Raphael Geissert wrote:

Hi, Portus 2.2 and older provides LDAP integration for authenticating the users. However, in spite of it providing 
advice on configuring it to "to setup LDAP over SSL/TLS"[1], the implementation does not verify the server's identity 
at all. I'm writing about it here mainly because there appears to be some intention of TLS support. Users might 
expect it to actually provide some kind of security. Interestingly enough, the documentation and the config file 
comments say 'the recommended [method] is "starttls".'[2] I don't know where they got that from. CC'ing SUSE's 
security team. I have not yet reported it to the portus team directly, nor requested a CVE id (though I'm tempted to 
request one, to err on the side of safety). [1]http://port.us.org/docs/Configuring-Portus.html 
[2]https://github.com/SUSE/Portus/blob/master/config/config.yml#L49 Cheers, -- Raphael Geissert

Current thread: