Re: Plaintext passwords

Simon Friedberger <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
> > a) The passwd approach:
> >        Pro: The server does not store the passwords.
> >        Con: The password has to be sent over the wire.
> > b) The CRAM-MD5 approach:
> >        Pro: The password is not sent over the wire.
> >        Con: The server has to store the password.
> 
> I'm not convinced these are the only two options. There are certainly
> authorization protocols in which the password only exists to create a
> hash, and neither side has the unencryted password stored.
> 
> ~ Anders

You are certainly right. Feel free to add anything. I only left out the
'obvious' certificate-login that Peter just mentioned because it
requires the user to carry around a usb-stick if he ever wants to use
jabber from a different machine, which frankly seems very incovenient.
(Then again maybe it's not that big a deal these days. *g*)
_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.