2 cyrus-sasl questions

1. Is there a scram sha-1 plugin by CMU ? If not, is there another one with a BSD-style licence
     that is recommended?

2. What is the best and most-secure way to use sendmail with sasl on *nix to connect to AD *without* keeping passwords in the clear? ("best" includes ease of administration.....)

