Re: Information about SASL and LDAP

> cmusaslsecretCRAM-MD5
> cmusaslsecretDIGEST-MD5 and
> cmusaslsecretNTLM

first of all thank you very much for all the answers. I decided to drop
ldapdb in favor of saslauthd and use SSHA passwords in the database
right now. I (or saying better: for our use case), we can force the
client user to use SSL/TLS for securing the password (the whole mail).

So this seems to be the compromise of having maximum security on
client-to-server and server-to-server communication. It's currently done
on the test setup. Are there any security aspects that would speak
against such a dicision?

