#4580 Investigate SSF values when SASL/GSSAPI is used to authenticate to LDAP
Closed: duplicate by cheimes. Opened by simo.

In the past SASL/GSSAPI has used a fixed value of 56 regardless of actual algorithm in use (which could be much stronger).

We should investigate how to make SASL bubble up the actual value so that proper minssf can be set in LDAP configuration.


We (Simo :) should try to investigate during 4.2 time frame.

Processing leftovers from 4.2 backlog - this ticket was found as suitable for consideration in next big feature release - 4.4.

Metadata Update from @simo:
- Issue assigned to simo
- Issue set to the milestone: FreeIPA 4.5 backlog

Metadata Update from @cheimes:
- Issue close_status updated to: duplicate
- Issue status updated to: Closed (was: Open)

The bug is more or less a duplicate of #7140.

master:

  • 350954589774499d99bf87cb5631c664bb0707c4 Require a minimum SASL security factor of 56
Metadata