[Kolab-devel] Password hashing

Roland Gruber gruberr at in.tum.de
Wed Mar 30 19:21:40 CEST 2005


Hi Kolab developers,

looks like LAM will be sponsored to support Kolab accounts. :)
Probably I will ask you some very LDAP specific questions in the near
future.

I created a user with the Kolab admin interface and noticed that the
password is hashed with SHA in LDAP.
How flexible is Kolab with password hashes? LAM supports CRYPT, SHA,
SSHA, MD5, SMD5 and plain text. Will Kolab work with all of them?

I think SSHA is the most secure one, maybe you have a special reason for
using SHA.

Is the password always stored hashed in LDAP? E.g. it could be possible
that kolabd takes plain text passwords on account creation for some
reason and then hashes the password in a second step.

Thanks a lot for your help.


Greetings,
Roland
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: OpenPGP digital signature
URL: <http://lists.kolab.org/pipermail/devel/attachments/20050330/abdbdb81/attachment.sig>


More information about the devel mailing list