Re: LDAP authentication without saslautd

Quanah Gibson-Mount <[email protected]> Wed, 14 Jun 2023 10:35:06 -0700
Newsgroups gmane.comp.security.cyrus.sasl
Message-ID <B28EC3A573C898E60B2845C2@[192.168.1.15]>

--On Monday, May 29, 2023 1:22 PM -0400 PFiver via SASL=20
<[email protected]> wrote:

> However, my setup includes an openLDAP instance where I store {SSHA}
> password. Thus I can not use the "auxprop" plugins.
>
>
> Is there a specific reason why none of the available mechanisms / plugins
> is supporting this setup?

Generally, I would say that since SASL is for SASL mechanisms, that would=20
be why.  With LDAP, a simple bind makes use of the userPassword attribute=20
and it doesn't matter what hashing mechanism is used underneath. SSHA is=20
very insecure at this point and we in the OpenLDAP project strongly advise=
=20
against using it.  With the current supported OpenLDAP release series, we=20
recommend using the argon2 support that's now available.

Are you not able to configure direct LDAP simple binds for your software?

Regards,
Quanah

------------------------------------------
Cyrus: SASL
Permalink: https://cyrus.topicbox.com/groups/sasl/T944af1261400714f-M28e346=
5f89af044e8cafb053
Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription