Access Control Rule in accessError template?

GEANT - Lukas Hämmerle lukas.haemmerle at switch.ch
Wed Jul 10 10:35:32 EDT 2013


On 10.07.13 15:56, Peter Schober wrote:
> Also I wouldn't want my access rules to be made public, esp. on access
> failure (even though they should not be exploitable simply by knowing
> them it might give information away that eases another attack,
> e.g. exposing userids which are allowed in, enabling targeted phishing
> etc.)

When asking this question I knew I would get a reply like yours :-) And
generally I completely agree. However, rules that authorize users based
on a group/organisation membership are less sensitive and therefore
might be ok to expose. Especially, if they are scoped.

And after all, its up to the administrator to decide what information he
wants to show in the error template.

Best Regards
Lukas


-- 
SWITCH
Lukas Hämmerle, Central Solutions
GÉANT GN3plus Task Leader "Enabling Users"
Werdstrasse 2, P.O. Box, 8021 Zurich, Switzerland
phone +41 44 268 15 05, direct +41 44 268 15 64
lukas.haemmerle at switch.ch, http://www.switch.ch


More information about the users mailing list