LDAP referrals and StartTLS

Cantor, Scott cantor.2 at osu.edu
Tue Jan 6 22:30:22 EST 2015


On 1/7/15, 3:22 AM, "Wessel, Keith" <kwessel at illinois.edu> wrote:



>Thanks, Daniel and Peter. I’ll file the “feature” request tomorrow.
> 
>I view it more as a bug because, had my AD allowed passwords over an 
>unencrypted channel, the follow-up query would have succeeded. But 
>because I had startTLS
> enabled for the data connector, I would have assumed that _all_ 
>connections would be encrypted. One could easily be sending their 
>credentials in the clear and not know it.
> 
>I understand where you’re coming from, but in my mind, this seems like a 
>security risk.

I would tend to agree, a lot of HTTP clients have/had similar issues with 
basic-auth options, where the client would follow redirects and then end 
up sending in the clear when the original options were telling it not to.

-- Scott



More information about the users mailing list