OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: A question about plain and cram-md5 authentication mechanisms

From: Patrick Ben Koetter (pstate-of-mind.de)
Date: Wed Nov 11 2009 - 16:37:27 CST


* Ali Majdzadeh <ali.majdzadehgmail.com>:
> Patrick,
> Thanks a lot for your help. I will test the mentioned configuration and will
> post the results to the list. I hope it works. Unfortunately, I do not have
> so much knowledge about LDAP, but I do know that it is possible to store
> Kerberos principals in an LDAP structure. Well, I don't know whether that is
> useful or not.

I think Victor put it right: You already have the best of both worlds with
PLAIN (low entry barrier, protection over TLS possible) and GSSAPI (high entry
barrier, protected in itself). Why go for CRAM-MD5, when this means you need
to lower the shields and store credentials in plain.

prick

--
state of mind
Digitale Kommunikation

http://www.state-of-mind.de

Franziskanerstraße 15 Telefon +49 89 3090 4664
81669 München Telefax +49 89 3090 4666

Amtsgericht München Partnerschaftsregister PR 563