Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Cisco: VOIP

security concern regarding cups

 

 

Cisco voip RSS feed   Index | Next | Previous | View Threaded


wael733 at hotmail

Nov 22, 2009, 9:28 AM

Post #1 of 5 (537 views)
Permalink
security concern regarding cups

Dears,

We have a security concern regarding cups.

When CUPS querying LDAP the integration account is sending the user name and password in plain text.

Can we use secure LDAP instead? And Also what is the advantage of the attached screen

Please advice.

Regards,
wael ahmed



_________________________________________________________________
Windows Live: Make it easier for your friends to see what you’re up to on Facebook.
http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_2:092009
Attachments: presence and ccx.jpg (192 KB)


voicenoob at gmail

Nov 23, 2009, 5:40 AM

Post #2 of 5 (490 views)
Permalink
Re: security concern regarding cups [In reply to]

Are you SURE it is sending the LDAP password in plaintext? Have you done a
packet capture? Also the screen shot you sent is the AXL configuration not
CUPS querying LDAP.



From: cisco-voip-bounces [at] puck
[mailto:cisco-voip-bounces [at] puck] On Behalf Of wael ahmed el
mezain
Sent: Sunday, November 22, 2009 11:29 AM
To: cisco-voip [at] puck
Subject: [cisco-voip] security concern regarding cups



Dears,



We have a security concern regarding cups.


When CUPS querying LDAP the integration account is sending the user name and
password in plain text.


Can we use secure LDAP instead? And Also what is the advantage of the
attached screen


Please advice.


Regards,

wael ahmed



_____

Windows Live: Make it easier for your friends to see what you
<http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/so
cial-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_2:092009
> 're up to on Facebook.


jason.aarons at us

Nov 23, 2009, 10:11 AM

Post #3 of 5 (488 views)
Permalink
Re: security concern regarding cups [In reply to]

Phone Messenger has same issue, I understand there is/will be fix for
the IP Phone Service to be https. Can't recall where I just read about
it -jason



From: cisco-voip-bounces [at] puck
[mailto:cisco-voip-bounces [at] puck] On Behalf Of VoiceNoob
Sent: Monday, November 23, 2009 8:40 AM
To: 'wael ahmed el mezain'; cisco-voip [at] puck
Subject: Re: [cisco-voip] security concern regarding cups



Are you SURE it is sending the LDAP password in plaintext? Have you done
a packet capture? Also the screen shot you sent is the AXL configuration
not CUPS querying LDAP.



From: cisco-voip-bounces [at] puck
[mailto:cisco-voip-bounces [at] puck] On Behalf Of wael ahmed el
mezain
Sent: Sunday, November 22, 2009 11:29 AM
To: cisco-voip [at] puck
Subject: [cisco-voip] security concern regarding cups



Dears,



We have a security concern regarding cups.


When CUPS querying LDAP the integration account is sending the user name
and password in plain text.


Can we use secure LDAP instead? And Also what is the advantage of the
attached screen


Please advice.


Regards,

wael ahmed



________________________________

Windows Live: Make it easier for your friends to see what you're up to
on Facebook.
<http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-actio
n/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_
2:092009>




-----------------------------------------
Disclaimer:

This e-mail communication and any attachments may contain
confidential and privileged information and is for use by the
designated addressee(s) named above only. If you are not the
intended addressee, you are hereby notified that you have received
this communication in error and that any use or reproduction of
this email or its contents is strictly prohibited and may be
unlawful. If you have received this communication in error, please
notify us immediately by replying to this message and deleting it
from your computer. Thank you.


wael733 at hotmail

Nov 24, 2009, 12:02 AM

Post #4 of 5 (489 views)
Permalink
Re: security concern regarding cups [In reply to]

Guys, thanks for reply



But anyone has solution for this ?

I used to get the solutions for my issues from this group.



Thanks,

Wael


Subject: RE: [cisco-voip] security concern regarding cups
Date: Mon, 23 Nov 2009 13:11:00 -0500
From: jason.aarons [at] us
To: voicenoob [at] gmail; wael733 [at] hotmail; cisco-voip [at] puck







Phone Messenger has same issue, I understand there is/will be fix for the IP Phone Service to be https. Can’t recall where I just read about it -jason



From: cisco-voip-bounces [at] puck [mailto:cisco-voip-bounces [at] puck] On Behalf Of VoiceNoob
Sent: Monday, November 23, 2009 8:40 AM
To: 'wael ahmed el mezain'; cisco-voip [at] puck
Subject: Re: [cisco-voip] security concern regarding cups

Are you SURE it is sending the LDAP password in plaintext? Have you done a packet capture? Also the screen shot you sent is the AXL configuration not CUPS querying LDAP.



From: cisco-voip-bounces [at] puck [mailto:cisco-voip-bounces [at] puck] On Behalf Of wael ahmed el mezain
Sent: Sunday, November 22, 2009 11:29 AM
To: cisco-voip [at] puck
Subject: [cisco-voip] security concern regarding cups

Dears,

We have a security concern regarding cups.

When CUPS querying LDAP the integration account is sending the user name and password in plain text.

Can we use secure LDAP instead? And Also what is the advantage of the attached screen

Please advice.

Regards,
wael ahmed




Windows Live: Make it easier for your friends to see what you’re up to on Facebook.





Disclaimer: This e-mail communication and any attachments may contain confidential and privileged information and is for use by the designated addressee(s) named above only. If you are not the intended addressee, you are hereby notified that you have received this communication in error and that any use or reproduction of this email or its contents is strictly prohibited and may be unlawful. If you have received this communication in error, please notify us immediately by replying to this message and deleting it from your computer. Thank you.

_________________________________________________________________
Windows Live: Keep your friends up to date with what you do online.
http://www.microsoft.com/middleeast/windows/windowslive/see-it-in-action/social-network-basics.aspx?ocid=PID23461::T:WLMTAGL:ON:WL:en-xm:SI_SB_1:092010


rratliff at cisco

Nov 24, 2009, 7:45 AM

Post #5 of 5 (487 views)
Permalink
Re: security concern regarding cups [In reply to]

For CUPS (the server) it pulls the ldap synchronization from the CUCM configuration. If you want this to be secure then configure LDAPS in CUCM.

On the CUPC clients the ldap searches they make can be configured to use TLS or anonymous bind (neither will have cleartext passwords on the wire). You configure TLS per-server in CUPS Application->CUPC->Ldap Server. The anonymous bind is configured in the Ldap Profile.

To use LDAPS from CUPS to AD you'll need to upload the certificate information to the CUPS OS page the same as CUCM.

-Ryan

On Nov 24, 2009, at 3:02 AM, wael ahmed el mezain wrote:

Guys, thanks for reply

But anyone has solution for this ?
I used to get the solutions for my issues from this group.

Thanks,
Wael
Subject: RE: [cisco-voip] security concern regarding cups
Date: Mon, 23 Nov 2009 13:11:00 -0500
From: jason.aarons [at] us
To: voicenoob [at] gmail; wael733 [at] hotmail; cisco-voip [at] puck

Phone Messenger has same issue, I understand there is/will be fix for the IP Phone Service to be https. Can’t recall where I just read about it -jason

From: cisco-voip-bounces [at] puck [mailto:cisco-voip-bounces [at] puck] On Behalf Of VoiceNoob
Sent: Monday, November 23, 2009 8:40 AM
To: 'wael ahmed el mezain'; cisco-voip [at] puck
Subject: Re: [cisco-voip] security concern regarding cups

Are you SURE it is sending the LDAP password in plaintext? Have you done a packet capture? Also the screen shot you sent is the AXL configuration not CUPS querying LDAP.

From: cisco-voip-bounces [at] puck [mailto:cisco-voip-bounces [at] puck] On Behalf Of wael ahmed el mezain
Sent: Sunday, November 22, 2009 11:29 AM
To: cisco-voip [at] puck
Subject: [cisco-voip] security concern regarding cups

Dears,

We have a security concern regarding cups.

When CUPS querying LDAP the integration account is sending the user name and password in plain text.

Can we use secure LDAP instead? And Also what is the advantage of the attached screen

Please advice.

Regards,
wael ahmed

Windows Live: Make it easier for your friends to see what you’re up to on Facebook.

Disclaimer: This e-mail communication and any attachments may contain confidential and privileged information and is for use by the designated addressee(s) named above only. If you are not the intended addressee, you are hereby notified that you have received this communication in error and that any use or reproduction of this email or its contents is strictly prohibited and may be unlawful. If you have received this communication in error, please notify us immediately by replying to this message and deleting it from your computer. Thank you.

Windows Live: Keep your friends up to date with what you do online. _______________________________________________
cisco-voip mailing list
cisco-voip [at] puck
https://puck.nether.net/mailman/listinfo/cisco-voip

Cisco voip RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.