draft-stroeder-hashed-userpassword-values-01

Michael Ströder <[email protected]> Wed, 13 Mar 2013 23:39:28 +0100
Newsgroups gmane.ietf.ldapext,gmane.comp.ldap.umich
Message-ID <[email protected]>
Kurt Zeilenga wrote:
> I see this document is marked as being intended to be published as
> Informational, but it reads more like it's trying to be a standard.

I tried to add some wording to avoid that misunderstanding in the next
revision of this draft:

http://www.ietf.org/internet-drafts/draft-stroeder-hashed-userpassword-values-01.txt

> I note that at Isode we have a 2307 style hash scheme that we use to hold
> SCRAM compatible hash.  Aside from being SCRAM compatible, it's designed to
> hinder dictionary and brute force attacks by significant increasing the
> cost of producing the stored value.   It would be good to include this as
> part of the 'current practice'.

I'd like to add that if you provide more detailed information about it.

Ciao, Michael.

_______________________________________________
Ldapext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ldapext
smime.p7s (application/pkcs7-signature, 3.8 KB) - not displayed