[Date Prev][Date Next] [Chronological] [Thread] [Top]

multi-valued userPassword (was: IETF ldapbis WG Last Call: draft-ietf-ldapbis-user-schema-05.txt)



HI!

Another issue:
Any reasonable *and* secure use-case for having multi-valued userPassword?

Maybe it's worth to note in section 'Security Considerations' that multiple attribute values for userPassword should be avoided. Especially reset/deletion of a password by an admin without knowing the old user password gets tricky or impossible if multiple values for different applications are present. This also somewhat relates to a similar discussion on ldap-ext list about possibly multi-valued attributes in draft-behera-ldap-password-policy.

The only use-case I could imagine for having multiple userPassword attribute values was working around the Octet String problem storing the *same* password with various character sets/encodings.

Ciao, Michael.