[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: (ITS#3472) return code should be 32 when no access to object



Of course, all my dscussion about write operations may sound academic, because writes need authentication; I guess we better focus on reads right now. Another note is: we don't check entry access for compares; this means that a compare should return noSuchObject as well if no disclose is granted for that entry, otherwise attackers could exploit it.

p.



   SysNet - via Dossi,8 27100 Pavia Tel: +390382573859 Fax: +390382476497