Re: Plaintext passwords
Simon Friedberger <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
> > a) The passwd approach: > > Pro: The server does not store the passwords. > > Con: The password has to be sent over the wire. > > b) The CRAM-MD5 approach: > > Pro: The password is not sent over the wire. > > Con: The server has to store the password. > > I'm not convinced these are the only two options. There are certainly > authorization protocols in which the password only exists to create a > hash, and neither side has the unencryted password stored. > > ~ Anders You are certainly right. Feel free to add anything. I only left out the 'obvious' certificate-login that Peter just mentioned because it requires the user to carry around a usb-stick if he ever wants to use jabber from a different machine, which frankly seems very incovenient. (Then again maybe it's not that big a deal these days. *g*) _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________