[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #3158 [Company]: Need a clearer policy about who gets ldap accounts



#3158: Need a clearer policy about who gets ldap accounts
---------------------+------------------------------------------------------
 Reporter:  arma     |          Owner:  phobos
     Type:  defect   |         Status:  new   
 Priority:  normal   |      Milestone:        
Component:  Company  |        Version:        
 Keywords:           |         Parent:        
   Points:           |   Actualpoints:        
---------------------+------------------------------------------------------

Comment(by rransom):

 I noticed when I received access to the Tor Git server that I had read
 access to the gitolite-admin repo, which contains the complete history of
 the list of all Git repos on git-rw.tpo and who has access to them.  (I
 confirmed that I had read access using âgit ls-remoteâ, not âgit cloneâ or
 any other command that would have actually retrieved the repository
 contents.)  If there is anything sensitive in there, we should restrict
 access to that repository before handing out LDAP accounts and Git access
 to people we know less well.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/3158#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs