[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1008672: debian-edu-config: Only fetch Debian Edu rootca once



Package: debian-edu-config
Version: 2.12.20
Severity: important

I noticed a change on Debian Edu clients between Debian 9 and 11 (unsure currently about Debian 10). In previous times, Debian Edu clients got prepared for LDAP connectivity to TJENER on first boot via obtaining the LDAP server's certificate. From then on the Debian Edu client would refuse talking to any other TJENER.

Migrating a Debian Edu client from one Debian Edu network to another, one would have to manually remove /etc/ldap/ssl/ldap-server-cert.pem (or what its name was).

With the new Debian Edu rootCA certificate (introduced with Debian Edu 10) being used as a base for authorizing the relationship between clients and the network server TJENER, I observe that when plugging one Debian Edu machine from one Debian Edu network into some other Debian Edu network the Debian Edu client machine would adjust itself to the new network (update Debian-Edu_rootCA.crt) during boot time.

For roaming workstations, this could indeed compromise home directory data stored on roaming workstations.

Attack scenario: your school provides you with a Debian Edu notebook (roaming workstation). This Debian Edu notebook was previously used by your teacher. Your teacher possibly copied over some exam documents or some such to that home (e.g. via a Nextcloud syncing app or some such).

The student takes this notebook home, sets up their own Debian Edu server, creates a user account with same userId of the student or the teacher itself, adds sudo permissions for this account and boom, the student has admin privileges on that notebook.

I'd suggest going back to the previous behaviour where a notebook would only attach itself to one Debian Edu TJENER on first boot and from then on be only authorized to talk to the LDAP server of that initial Debian Edu network it was booted in.

Comments? Feedback?

Mike
--

DAS-NETZWERKTEAM
c\o Technik- und Ökologiezentrum Eckernförde
Mike Gabriel, Marienthaler Str. 17, 24340 Eckernförde
mobile: +49 (1520) 1976 148
landline: +49 (4351) 850 8940

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

Attachment: pgpUXgVvx0eJs.pgp
Description: Digitale PGP-Signatur


Reply to: