Re: DBIS - new IETF drafts
Luke Howard <[email protected]> Sat, 11 Jan 2014 01:15:03 +1100
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Message-ID | <[email protected]> |
>> Every LDAP-aware client system that I have worked with can use the >> bind operation as a means to validate passwords, so the only >> possible excuse for exporting hashes is temporary support of >> migrating systems. If you only allow the export of hashes that are >> actually needed by the old non-LDAP systems then at least you are >> not making matters worse than they were before the migration. > > Ok, so I posed this question just now, but can all LDAP servers you can think of authentication bind operations using CRYPT-style passwords? If it can be done server-side there'll be no problem here and we need never expose the hashes to clients. Active Directory cannot. -- Luke