Howard Chu
2006-Nov-09 18:49 UTC
Re: [Fedora-directory-users] PAM passthru questions and SecureID
> Date: Wed, 08 Nov 2006 15:08:02 -0800 > From: Chris Maresca <ckm@olliancegroup.com>> Richard Megginson wrote:>> I just don''t like overloading the userPassword {foo} syntax, but >> openldap has a history of doing something similar with {kerberos} and >> {sasl}, so there is precedent.They''re also strongly deprecated; {kerberos} is no longer supported. The only real need for them is old clients that only know how to do Simple Bind. Since that in itself is a security liability, it''s better to get the clients updated. -- -- Howard Chu Chief Architect, Symas Corp. http://www.symas.com Director, Highland Sun http://highlandsun.com/hyc OpenLDAP Core Team http://www.openldap.org/project/
Chris Maresca
2006-Nov-09 19:20 UTC
Re: [Fedora-directory-users] PAM passthru questions and SecureID
Howard Chu wrote:> it''s better to get the clients updated.Sure, that''s a realistic option..... Chris. -- Chris Maresca Founding Partner Olliance Group, LLC www.olliancegroup.com +1.650.331.1770 x201