<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, Apr 2, 2015 at 4:54 AM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Derp Niner &lt;<a href="mailto:derpniner@gmail.com">derpniner@gmail.com</a>&gt; [2015-04-02 03:03]:<br>
<span class="">&gt; I would like to know which one is preferred (and why if you have a<br>
&gt; few minutes to explain).<br>
<br></span>One simple answer is that there is no specification for LDAPS, it&#39;s<br>
only a de facto &quot;standard&quot;.<br>
OTOH the LDAP Technical Specifications (RFC4510) also contain RFC4513<br>
which has an implementation requirement for StartTLS if you wanted to<br>
support Simple binds (not SASL authn method).<br>
So if you cared about Internet Standards you have your answer.<br></blockquote><div><br></div><div>In addition to what Peter said, startTLS functionality in Java has better APIs built around it.</div><div>Since most directories support startTLS it made sense to be the default option.</div><div><br></div><div>--Daniel Fisher</div><div> </div></div></div></div>