On Mar 29, 2006, at 2:21 PM, Mario Olimpio de Menezes wrote:

On Tuesday 28 March 2006 21:55, Georges Racinet wrote:
Also worth of notice: all attempts to fetch the user's password from
CPS will return an empty string. This is primarily to ensure protection

how one is supposed to authenticate?
can I still fetch the user password from the LDAP or is exactly this that is
prevented in CPS?

This is exactly what's prevented.

The auth part has nothing to do with fetching the password. Instead, at login time, the LDAP server asks the user to send his password and does the checking itself. This is standard. That's why I wrote that it's transparent for auth questions. Authentication against protected passwords has always been possible in CPS: it's just not CPS' problem.

I'm having problems right now with CPSLDAPSetup that I didn't have with LDAPUserFolder. My site used to work before the upgrade to CPSLDAPSetup.

I hope someone can help me before I downgrade to 3.3.8.1 with
LDAPUserFolder :-(

Sorry, too busy to help you right now, but you sounded more optimistic than that in your last post.

---------
Georges Racinet                        Nuxeo SAS
[EMAIL PROTECTED]                http://nuxeo.com
Tel: +33 (0) 1 40 33 71 73


_______________________________________________
cps-users mailing list
[email protected]
http://lists.nuxeo.com/mailman/listinfo/cps-users

Reply via email to