Re: [SSSD] Securing remote domains

2012-05-24 Thread Edward Z. Yang
Excerpts from Stephen Gallagher's message of Wed May 23 08:12:33 -0400 2012: > I'm working under the assumption that when you speak of "local domains" > here, you're talking about /etc/passwd. If this is wrong, please correct > me. Yes, we are in agreement here. > This means that any lookup calli

[SSSD] Securing remote domains

2012-05-22 Thread Edward Z. Yang
Hello all, We're interested in using SSSD to replace our current use of NSS/PAM/NSCD/NSLCD. However, we were curious whether or not SSSD had implemented some critical security checks to protect against malicious remote domains. - What are the semantics of the local domain: that is, do