T 3.87 Improper configuration of directory services

A faulty software configuration is one of the most common reasons for the success of an attack. In the case of directory services, the high level of complexity and the large number of parameters available can lead to additional security problems due to overlooked side-effects. Faulty configurations can have a particularly serious impact in the following areas:

In general, the configuration of a system needs to be based on its security policy. If there is a faulty configuration, then there is a risk that the security policy will be implemented inadequately or incorrectly, which means it will be impossible to achieve the objectives of the security policy.

The configuration of a role-based administration for the directory system as well as a delegation of administration rights are generally primary features of a directory service. Incorrect configuration of these features can, under certain circumstances, lead to significant problems due to unauthorised system access. Furthermore, there is a risk that proper administration will be impossible if this feature is configured incorrectly.

The following list shows possible security-related consequences resulting from an incorrect configuration of the directory service: