Re: Using Notes for User Authentication

Ingo Boernig <[email protected]>
Newsgroups gmane.linux.suse.domino
Message-ID <[email protected]>
On Tue, Jul 22, m0s3r wrote:

> used by the app. The pw is encrypted. But if the app knows, how domino 
> encrypts the field, the app. can encrypt the users not encrypted pw and 
> then compare the LDAP-entry with the tipped and encrypted pw.
> How does domino encrypt the pw?
> Or is it quite simpler?

Then you would allow anonymous uses access to the encrypted password and
thats not very desirable. Normally you do it this way: Try to bind to
the LDAP server with the binddn of the user and send the tipped password
to the server. If the bind succeeds, the password has been correct. This
is how pam_ldap is working in Linux, for instance. 

The problem is, that you have to send the unencrypted tipped password
over the network. So you should consider to secure your LDAP connection
via TLS or SSL.

> Marc

-- 
Ingo Börnig -  SuSE Linux AG Partner Services  -  Enterprise Solutions
        Marie-Curie-Straße 11-17  -   D-53757 St. Augustin
Tel.:+49-2241-92917-43 	 			Fax:+49-2241-314599911
Office Dortmund: Tel.:+49-179-1277636     E-Mail: [email protected]
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux)

iD8DBQE/HVJh+Ps8YyAzvzIRAqkAAKCbFT29fetAzxOPGJUp1ekRLReKrwCggF9I
PYzc5Mn9ej/hqF0RdP5dKEc=
=FcAX
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.