Re: [ldapext] draft-stroeder-hashed-userpassword-values-01

Michael Ströder <michael-rG38yQ/2uf9Wk0Htik3J/[email protected]> Thu, 14 Mar 2013 15:31:28 +0100
Newsgroups gmane.comp.ldap.umich,gmane.ietf.ldapext
Message-ID <[email protected]>
Ludovic Poitou wrote:
> I'm glad that you've added text to support {CRYPT}. But I'm not sure it is
> necessary to make the description complete (i.e. refer to all underlying
> platform specific algorithm).
> I think it might be enough to describe the general format of passwords
> generated by the crypt(3) library, mentions the default unix crypt and one or
> two other algorithm, but also warn that crypt being extensible and platform
> specific, it's use might result in interoperability issues.

That's exactly what I did even without describing any of the algorithms.

> I would suggest that you add to the list of schemes, PBKDF2 and BCrypt that
> are 2 mechanisms that are providing much stronger security than the SHA 1 or 2.
> I'be happy to provide a description of PBKDF2 if you want, as we've
> implemented support for it in OpenDJ.

I'm glad to see PBKDF2 appearing in LDAP server implementations.
Yes, please provide text to be added.

Ciao, Michael.
smime.p7s (application/pkcs7-signature, 3.8 KB) - not displayed