Andy Schofield wrote:
Not from the DS point of view - if it accepts a hashed password in the bind then that is equivalent to the original password, so nothing is really achieved. It /may/ delay the ability of an attacker to log in to a machine using LDAP as the authentication mechanism, but md5 has known vulnerabilities in that regard and cannot be recommended.However, a hashed password is better than nothing surely. Even NISdidn't sent passwords in the clear.
-- Pete
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
-- Fedora-directory-users mailing list Fedora-directory-users@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-directory-users