Comment 4 for bug 109270

Revision history for this message
Michael Shigorin (shigorin) wrote :

There's no secure way to provide user list to ldm only, except by using public key cryptography I think -- and that would be overkill.

I see no problem with something that can be enabled or disabled at server side "that could be exploited to find out user names simply" since things like that are admin policy decision, no less and no more. Judging this idea as "good" or "bad" is deciding for all the admins out there who might need or oppose such a feature, but insisting that a person who would oppose it should implement it is broken as well -- so while I'm pretty happy with kdm/xdmcp-way providing our customers with the functionality needed, it's no problem that this cannot be done with ldm.

No more agitation I hope ;-)