|
Shalom, If you are going to promote selling your book and information here then you should at least provide the full explanation of what you are alleging. The interface you are referring to is available on the IBM Directory Server for OS/400, AIX and z/OS. It has different names on each platform but it is available and it is read/write not just read. When a request is made to the directory context for the projected backend the Directory Server uses APIs rather than database calls to service the request. This keeps you (or OS400) from having to synchronize account data between the user repository and the directory. When a client sends a modify, add or delete operation for a user to the server it will format the corresponding OS400 CRTUSRPRF, DLTUSRPRF or CHGUSRPRF command and attempt to execute it. What is the most important to note is that in order to use the projected backend you must be authenticated using a projected user account. This is required so that the directory server can service the request under the authority of the client. Bottom line is that you can't get a list of users that you do not have authority to see and likewise you can't modify users you don't have authority to. Having the LDAP server open is no smaller or greater risk than having the telnet server open. If it is then I'd argue that you have more serious security issues to deal with than worrying about this. I talked to THE OS400 Security Expert about this alleged exposure a few weeks ago and their response was that this is not an issue. Kurt -----Original Message----- From: midrange-l-bounces@xxxxxxxxxxxx [mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of shalom@xxxxxxxxxx Sent: Sunday, April 17, 2005 9:35 AM To: midrange-l@xxxxxxxxxxxx Subject: RE: LDAP Hey, You can't create new system user profiles via LDAP. You can only list system user profiles via LDAP. For an interesting example of the security problem this may present, read the relevant article on my web site, at www.venera.com/downloads.htm (or just google for as400 ldap) Shalom Carmel -- This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list To post a message email: MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/midrange-l or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting, please take a moment to review the archives at http://archive.midrange.com/midrange-l.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.