[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: I-D ACTION:draft-zeilenga-ldap-authpasswd-03.txt



I have added to "Background and Intended Usage"

Storage schemes often use of cryptographic strength one-way hashing. 
Though the use of one-way hashing reduces the potential that exposed
values will allow unauthorized access to the Directory (unless the 
hash algorithm/implementation is flawed), the hashing of passwords
is intended to be as an additional layer of protection.  It is
RECOMMENDED that hashed values be protected as if they were clear 
text passwords.

and to "Security Considerations"

As flaws may be discovered in the hashing algorithm or with a 
particular implementation of the algorithm, values of AuthPassword
SHOULD be protected as if they were clear text passwords.  When  
values are transferred, privacy protections, such as IPSEC or TLS,
SHOULD be in place.