Security impact of nscd and NSS module bugs (particularly NIS)

Rich Felker dalias@libc.org
Sat Jul 5 03:00:00 GMT 2014


On Fri, Jul 04, 2014 at 12:22:58PM -0700, Roland McGrath wrote:
> > If nscd crashes and unwanted in-process NSS module fallback is a 
> > concern, maybe we could add some construct that once nscd has been 
> > started first, fallback is disabled?  Would that make sense?
> 
> Plausible.  Today there is no client-side configuration related to nscd at
> all.  So you'd have to come up with something.

Isn't just eliminating the unwanted modules from /etc/nsswitch.conf
the natural way to prevent fallback on the client side?

Rich



More information about the Libc-alpha mailing list