<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Tue, Jan 6, 2015 at 10:22 PM, Wessel, Keith <span dir="ltr"><<a href="mailto:kwessel@illinois.edu" target="_blank">kwessel@illinois.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">Thanks, Daniel and Peter. I’ll file the “feature” request tomorrow.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">I view it more as a bug because, had my AD allowed passwords over an unencrypted channel, the follow-up query would have succeeded. But because I had startTLS
enabled for the data connector, I would have assumed that _<i>all</i>_ connections would be encrypted. One could easily be sending their credentials in the clear and not know it.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">I understand where you’re coming from, but in my mind, this seems like a security risk.</span></p></div></div></blockquote><div><br></div><div>It certainly is, but it feels like a misconfiguration rather than a bug.</div><div>Your directory is sending referrals and you've configured the IDP to follow them, but I don't want to argue semantics.</div><div>How do you think this should work?</div><div>My first thought was to provide a component like StartTLSReferralHandler that you would have to configure, it would attempt to startTLS on any referrals.</div><div>One of the problems with relying on referrals is that you don't benefit from connection pooling, that may be a feature worth adding as well.</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>