On Wed, 6 Mar 2019 14:33:49 +0100
Mark Rotteveel <m...@lawinegevaar.nl> wrote:

> 
> Srp is not a legacy authentication, it is just slightly less secure
> than Srp256


I'm wondering then if I understand the difference between AuthServer and
AuthClient. My understanding is that AuthServer specifies the plugins
the server will use to authorize client attachments. AuthClient
specifies the plugins the client will use to make the initial connect
to the server. So if we have the current default of

  AuthServer = Srp256

then surely an FB3 client that uses Srp will be rejected? 

If my understanding is correct srp is a form of legacy authorization,
even if it does not use the legacy_auth plugin.


Paul
-- 

Paul Reeves
http://www.ibphoenix.com
Supporting users of Firebird
 


Firebird-Devel mailing list, web interface at 
https://lists.sourceforge.net/lists/listinfo/firebird-devel

Reply via email to