Hello,

reading RFC 2251 (pages 20 - 22), I understood that if a client uses the
simple authentication mechanism then the password must be in clear text.

Am I right or wrong?
Are there any means to exchange a non-clear text password (e.g. encrypted or
hashed) between a client and a server?
Are there any means to store a non-clear text password (e.g. encrypted or
hashed) on the directory server database?

Thank you

Laurent

Reply via email to