LDAP defaults
Mike Schwartz
mike at gluu.org
Fri Oct 2 00:02:15 EDT 2015
One issue is that in some cases you'll fail a security audit. Although I
agree that it would only be a minor inconvenience for a hacker to
decrypt.
We have some code that we use for encrypting properties in the Gluu
Server. It would also require the admin to run a script on the password
to encrypt. Maybe we can prefix with something to signal that the
password is encrypted to not bother those who want to keep using clear
text.
- Mike
2015-10-01 23:53, Cantor, Scott wrote:
> On 10/1/15, 4:26 PM, "dev on behalf of Mike Schwartz"
> <dev-bounces at shibboleth.net on behalf of mike at gluu.org> wrote:
>
>> BTW, one thing that always bugged me is that the LDAP Bind Creds are
>> put
>> in plain text. Can't you make it at least a little hard?
>
> I'm not seeing the value, but if somebody else wants to contribute
> something, it probably would have to be the Spring layer to be worth
> doing. Maybe somebody already wrote something.
>
> -- Scott
--
-------------------------------------
Michael Schwartz
Gluu
Founder / CEO
mike at gluu.org
More information about the dev
mailing list