Hi,

> Personally think that clear text is bad as anyone intercepting the
> packets can easily pick up anything in clear text.

You mean intercepting the packets between LDAP server and
RADIUS server (since the communication with the RADIUS client
isn't affected anyway)? But knowing the LM or NT password is
sufficient to log in anyway, if you spend some minutes to modify
some open source client accordingly , isn't it? You don't need
the clear text password anyway in Windows' authentications scheme,
AFAICT, so what's the point?

        Regards,
                Stefan



-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to