Activity log for bug #1159770

Date Who What changed Old value New value Message
2013-03-25 12:50:47 Paul Boven bug added bug
2013-03-25 12:51:43 Paul Boven description The file /etc/ldap.conf contains the settings for LDAP authentication. The recommended way of configuring this file and LDAP authentication, is through debconf. However, there is no way to specify whether TLS or SSL must be used for LDAP authentication, and without this setting, the user passwords will be sent in cleartext over the network. Release: Ubuntu 12.04.2 LTS Version: ldap-auth-config: Installed: 0.5.3 Expected: To be able to set up secure LDAP authentication through debconf Instead: Configuring that TLS or SSL is required, is not possible. This also means that it cannot be preseeded during automated installs. To enable TLS or SSL, the /etc/ldap.conf must contain "ssl start_tls' or 'ssl on' as appropriate. These are available already in the file, but currently commented out. These can be failry easyily brought under debconf control, would only require a new question in control/Templates, and code in control/postinst. The file /etc/ldap.conf contains the settings for LDAP authentication. The recommended way of configuring this file and LDAP authentication, is through debconf. However, there is no way to specify whether TLS or SSL must be used for LDAP authentication, and without this setting, the user passwords will be sent in cleartext over the network. Release: Ubuntu 12.04.2 LTS Version: ldap-auth-config: Installed: 0.5.3 Expected: To be able to set up secure LDAP authentication through debconf Instead: Configuring that TLS or SSL is required, is not possible. This also means that it cannot be preseeded during automated installs. To enable TLS or SSL, the /etc/ldap.conf must contain "ssl start_tls' or 'ssl on' as appropriate. These are available already in the file, but currently commented out. These can be failry easily brought under debconf control, would only require a new question in control/Templates, and code in control/postinst.
2013-03-25 16:42:14 Paul Boven bug watch added http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=432537
2013-03-25 16:52:51 Paul Boven attachment added ldap-auth-config_sever-ssl.patch https://bugs.launchpad.net/ubuntu/+source/ldap-auth-client/+bug/1159770/+attachment/3596385/+files/ldap-auth-config_sever-ssl.patch
2013-03-25 20:16:26 Ubuntu Foundations Team Bug Bot tags patch
2013-03-25 20:16:36 Ubuntu Foundations Team Bug Bot bug added subscriber Ubuntu Sponsors Team
2013-03-26 15:35:02 Daniel T Chen ldap-auth-client (Ubuntu): importance Undecided Wishlist
2013-03-26 15:35:02 Daniel T Chen ldap-auth-client (Ubuntu): status New Triaged
2013-03-28 22:05:28 Brian Murray tags patch patch precise
2013-03-28 22:06:08 Brian Murray removed subscriber Ubuntu Sponsors Team