milux / ctldap

LDAP Wrapper for ChurchTools
GNU General Public License v3.0
12 stars 8 forks source link

Doemon is always listening on 0.0.0.0 #18

Closed a-schild closed 4 years ago

a-schild commented 5 years ago

The ldap daemon is always listening on public internet 0.0.0.0, so the ldap server is open to all network requests.

By default it should only listen on 127.0.0.1, so the admin has to enable "public" access if required. (Secure defaults)

See patch for this in fork a-schild

milux commented 4 years ago

Included with merge of churchtools/ctldap-ms, closing.