LDAP defaults

Mike Schwartz mike at gluu.org
Fri Oct 2 00:02:15 EDT 2015


One issue is that in some cases you'll fail a security audit. Although I 
agree that it would only be a minor inconvenience for a hacker to 
decrypt.

We have some code that we use for encrypting properties in the Gluu 
Server.  It would also require the admin to run a script on the password 
to encrypt. Maybe we can prefix with something to signal that the 
password is encrypted to not bother those who want to keep using clear 
text.


- Mike






  2015-10-01 23:53, Cantor, Scott wrote:
> On 10/1/15, 4:26 PM, "dev on behalf of Mike Schwartz"
> <dev-bounces at shibboleth.net on behalf of mike at gluu.org> wrote:
> 
>> BTW, one thing that always bugged me is that the LDAP Bind Creds are 
>> put
>> in plain text. Can't you make it at least a little hard?
> 
> I'm not seeing the value, but if somebody else wants to contribute
> something, it probably would have to be the Spring layer to be worth
> doing. Maybe somebody already wrote something.
> 
> -- Scott

-- 
-------------------------------------
Michael Schwartz
Gluu
Founder / CEO
mike at gluu.org


More information about the dev mailing list