LDAP referrals and StartTLS
Cantor, Scott
cantor.2 at osu.edu
Tue Jan 6 22:30:22 EST 2015
On 1/7/15, 3:22 AM, "Wessel, Keith" <kwessel at illinois.edu> wrote:
>Thanks, Daniel and Peter. I’ll file the “feature” request tomorrow.
>
>I view it more as a bug because, had my AD allowed passwords over an
>unencrypted channel, the follow-up query would have succeeded. But
>because I had startTLS
> enabled for the data connector, I would have assumed that _all_
>connections would be encrypted. One could easily be sending their
>credentials in the clear and not know it.
>
>I understand where you’re coming from, but in my mind, this seems like a
>security risk.
I would tend to agree, a lot of HTTP clients have/had similar issues with
basic-auth options, where the client would follow redirects and then end
up sending in the clear when the original options were telling it not to.
-- Scott
More information about the users
mailing list