Commit aef44759 authored by Simon McVittie's avatar Simon McVittie

dbus-daemon(1): Recommend requiring EXTERNAL on non-Windows OSs

This is the default, and blocks TCP-based attacks by making the
attacker fail to authenticate (while also preventing inadvisable
TCP-based configurations from working).

Bug: Simon McVittie's avatarSimon McVittie <>
Reviewed-by: Ralf Habacker's avatarRalf Habacker <>
Reviewed-by: Philip Withnall's avatarPhilip Withnall <>
parent 5d368048
......@@ -491,6 +491,10 @@ exist, then all known mechanisms are allowed. If there are multiple
&lt;auth&gt; elements, all the listed mechanisms are allowed. The order in
which mechanisms are listed is not meaningful.</para>
<para>On non-Windows operating systems, allowing only the
<literal>EXTERNAL</literal> authentication
mechanism is strongly recommended. This is the default for the
well-known system bus and for the well-known session bus.</para>
<para>Example: &lt;auth&gt;EXTERNAL&lt;/auth&gt;</para>
