× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



Shalom,

If you are going to promote selling your book and information here then you
should at least provide the full explanation of what you are alleging.  

The interface you are referring to is available on the IBM Directory Server
for OS/400, AIX and z/OS.  It has different names on each platform but it is
available and it is read/write not just read.  When a request is made to the
directory context for the projected backend the Directory Server uses APIs
rather than database calls to service the request.  This keeps you (or
OS400) from having to synchronize account data between the user repository
and the directory.  When a client sends a modify, add or delete operation
for a user to the server it will format the corresponding OS400 CRTUSRPRF,
DLTUSRPRF or CHGUSRPRF command and attempt to execute it.  What is the most
important to note is that in order to use the projected backend you must be
authenticated using a projected user account.  This is required so that the
directory server can service the request under the authority of the client.
Bottom line is that you can't get a list of users that you do not have
authority to see and likewise you can't modify users you don't have
authority to.  Having the LDAP server open is no smaller or greater risk
than having the telnet server open.  If it is then I'd argue that you have
more serious security issues to deal with than worrying about this.

I talked to THE OS400 Security Expert about this alleged exposure a few
weeks ago and their response was that this is not an issue.  

Kurt

-----Original Message-----
From: midrange-l-bounces@xxxxxxxxxxxx
[mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of shalom@xxxxxxxxxx
Sent: Sunday, April 17, 2005 9:35 AM
To: midrange-l@xxxxxxxxxxxx
Subject: RE: LDAP

Hey,
You can't create new system user profiles via LDAP.

You can only list system user profiles via LDAP. 
For an interesting example of the security problem this may present,
read the relevant article on my web site, at www.venera.com/downloads.htm

(or just google for as400 ldap)

Shalom Carmel
-- 
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: MIDRANGE-L@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at http://archive.midrange.com/midrange-l.


As an Amazon Associate we earn from qualifying purchases.

This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.