Re: DBIS - new IETF drafts

Luke Howard <[email protected]> Sat, 11 Jan 2014 01:15:03 +1100
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
>> Every LDAP-aware client system that I have worked with can use the
>> bind operation as a means to validate passwords, so the only
>> possible excuse for exporting hashes is temporary support of
>> migrating systems. If you only allow the export of hashes that are
>> actually needed by the old non-LDAP systems then at least you are
>> not making matters worse than they were before the migration.
> 
> Ok, so I posed this question just now, but can all LDAP servers you can think of authentication bind operations using CRYPT-style passwords?  If it can be done server-side there'll be no problem here and we need never expose the hashes to clients.

Active Directory cannot.

-- Luke