LDAP-Security
From UGCS
Security Measures:
- LDAP CA on head LDAP server
- Restrict LDAP directory access to ldaps+SASL auth
- Users may modify their own name/userinfo/path/shell fields
- Users may not modify their UID, home directory, group membership, or caltech-uid
- Users may lookup other users' info, except their caltech-uid