| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
3.5.3.9.1 Directory Services (Page 3 of 3) Directory Services Security Issues Some directory services allow anyone to query the directory for any available information about network resources and users. Still other directory services support multiple forms of authentication allowing the administrator to choose the most appropriate mechanism (hint: challenge/response or PKI based authentication schemes, discussed further in the following chapter, are more secure than those which transmit a password in encrypted or clear text forms). With authentication, different levels of users can be granted different levels of access, helping enforce the security principle of providing information on a need to know basis only.
Information provided by directory services can include sensitive details about the enterprise and its network configuration types of data that you wouldnt want an attacker with a network packet sniffer to have. Therefore, many directory services can make use of encryption when sending data back and forth between directory service client and server. If your directory service supports an encrypted communication path, use it. If youre using vanilla LDAP, consider moving to LDAP over TLS, which provides such encryption.
A last subtle point to consider when hardening a directory server is verifying that the directory contains correct data. Has the data been obtained through appropriate, verified channels? If you dont have established, verifiable sources for data, someone might very well be able to insert bogus information into your directory without any sort of technical access to it at all (in yet another case of social engineering). __________________ 381. http://www.windowsadvantage.com/tech_edge/04-16-01_alleged_flaw.asp 382. http://www.microsoft.com/technet/treeview/default.asp?url=/technet/Security/Bulletin/ms00-026.asp
Home - Table Of Contents - Contact Us CertiGuide for Security+ (http://www.CertiGuide.com/secplus/) on CertiGuide.com Version 1.0 - Version Date: November 15, 2004 Adapted with permission from a work created by Tcat Houser et al. CertiGuide.com Version © Copyright 2004 Charles M. Kozierok. All Rights Reserved. Not responsible for any loss resulting from the use of this site. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||