Re: [Freeipa-users] MinSSF suggestions?

2014-08-14 Thread Erinn Looney-Triggs
On Wednesday, August 13, 2014 08:57:19 PM Rob Crittenden wrote: Erinn Looney-Triggs wrote: On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On

Re: [Freeipa-users] MinSSF suggestions?

2014-08-13 Thread Rob Crittenden
Erinn Looney-Triggs wrote: On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon, Aug 11, 2014 at

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash:

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Alexander Bokovoy
On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: On Sat, 09 Aug 2014, Erinn Looney-Triggs

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon,

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon,

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Alexander Bokovoy
On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: I guess the part I don't get here, is that this setting does not disable anonymous access to rootdse it just requires, as far as I understand, that TLS or some security be used for the connection. I currently have minssf set to 56 and am able to

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 12:33 PM, Alexander Bokovoy wrote: On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: I guess the part I don't get here, is that this setting does not disable anonymous access to rootdse it just requires, as far as I understand, that

Re: [Freeipa-users] MinSSF suggestions?

2014-08-11 Thread Alexander Bokovoy
On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It would seem to be prudent to set the minssf setting for 389 to 56, however I am wondering why this isn't done by default, and if there is any reason why I shouldn't do it? Anonymous connection to

Re: [Freeipa-users] MinSSF suggestions?

2014-08-11 Thread Jakub Hrozek
On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It would seem to be prudent to set the minssf setting for 389 to 56, however I am wondering why this isn't done by default, and

Re: [Freeipa-users] MinSSF suggestions?

2014-08-11 Thread Martin Kosek
On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It would seem to be prudent to set the minssf setting for 389 to 56, however I am

[Freeipa-users] MinSSF suggestions?

2014-08-09 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It would seem to be prudent to set the minssf setting for 389 to 56, however I am wondering why this isn't done by default, and if there is any reason why I shouldn't do it? Thanks, - -Erinn -BEGIN PGP SIGNATURE- Version: GnuPG v1