Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1251759

Bug#1108711: ldapvi: please provide option to read bind password from file

From Ansgar <ansgar@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#1108711: ldapvi: please provide option to read bind password from file
Date 2025-07-03 18:10 +0200
Message-ID <L4uFA-eYXK-1@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


Package: ldapvi
Version: 1.7-11.1+b1
Severity: wishlist
Tags: upstream
X-Debbugs-Cc: ldapvi@lists.askja.de

Hi,

ldapvi has an option to pass the bind password via a command-line
parameter:

  -w, --password SECRET  Password (also valid for SASL).

However passing credentials in this way is often insecure as other
local users/processes can see command-line parameters of all running
programs.

It would be great if one could ask ldapvi to use the contents of a
file as the password, similar to OpenLDAP's command-line utilities
(ldapsearch & others):

       -y passwdfile
              Use complete contents of passwdfile as the password for simple authentication.

If this was implemented, one could pass credentials from a password
manager to ldapvi in a more secure fashion without having to manually
paste it at the right time. (I have convenience wrappers around
ldapsearch to invoke it with `-y $(password-manager)` so it just
works.)

Ansgar

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1108711: ldapvi: please provide option to read bind password from file Ansgar <ansgar@debian.org> - 2025-07-03 18:10 +0200
  Bug#1108711: ldapvi: please provide option to read bind password from file brice@waegenei.re - 2025-07-15 17:30 +0200

csiph-web