Re: LDAP authentication without saslautd
Quanah Gibson-Mount <[email protected]> Wed, 14 Jun 2023 10:35:06 -0700
| Newsgroups | gmane.comp.security.cyrus.sasl |
|---|---|
| Message-ID | <B28EC3A573C898E60B2845C2@[192.168.1.15]> |
--On Monday, May 29, 2023 1:22 PM -0400 PFiver via SASL=20 <[email protected]> wrote: > However, my setup includes an openLDAP instance where I store {SSHA} > password. Thus I can not use the "auxprop" plugins. > > > Is there a specific reason why none of the available mechanisms / plugins > is supporting this setup? Generally, I would say that since SASL is for SASL mechanisms, that would=20 be why. With LDAP, a simple bind makes use of the userPassword attribute=20 and it doesn't matter what hashing mechanism is used underneath. SSHA is=20 very insecure at this point and we in the OpenLDAP project strongly advise= =20 against using it. With the current supported OpenLDAP release series, we=20 recommend using the argon2 support that's now available. Are you not able to configure direct LDAP simple binds for your software? Regards, Quanah ------------------------------------------ Cyrus: SASL Permalink: https://cyrus.topicbox.com/groups/sasl/T944af1261400714f-M28e346= 5f89af044e8cafb053 Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription