Re: Plaintext passwords
Peter Saint-Andre <[email protected]>
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
Norman Rasmussen wrote: > My personal server uses pam for authentication, so users _have_ to use > plaintext authentication via TLS, and if they want to change their > passwords, they have to use passwd via ssh. It's pretty secure, but > hard to scale for services like jabber.org Er, yeah, that's not going to work at jabber.org -- we have 300k+ users. Because we don't have email addresses on file for our users, we don't have an automated way for people to request lost passwords (users can change their passwords via XEP-0077, but that doesn't work if you have forgotten your password). Currently when someone forgets their password, they contact me directly and I manually change their password. That approach doesn't scale, but I typically receive only one request a day so it's not really a big deal. However, this forces us to store plaintext passwords. Of course, the beauty of Jabber is that if you don't like this policy, you can always run your own server. :) Peter -- Peter Saint-Andre https://stpeter.im/ _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________