From: Milan B. <mi...@km...> - 2004-09-23 10:16:31
|
Alex Peshkov wrote: > It seems to me that I've described them in my letter - we can't prevent > stealing hashes of passwords (at least for CS on posix). Current hashes > may be relatively easy brutforced on a modern CPUs. Therefore let's try > to make them hard to brutforce. The best way is to let people use that > hashes they trust. Therefore - crypt plugins. Has anyone considered using LDAP for authentication (as an alternative)? Firebird would only need to hook up to LDAP and use it's mechanism for storing/checking passwords. It would enable easier administration (for users) and leave the password issue to the tool that is specialized for it. Just my $0.02. -- Milan Babuskov http://fbexport.sourceforge.net http://www.flamerobin.org |