On Tue, Dec 12, 2006 at 04:21:41PM +0100, Ralph R????ner wrote:
> If so then there is a problem that I cannot solve: The
> challenge-response Authentication mechanism between User Agent and LDAP
> must exchange messages, and the web site in the middle must forward
> them back and forth, including protocol conversion between whatever the
> User Agent implements (HTTP digest authentication?) and the SASL library
> in the LDAP. I would guess that there is no ready solution for this but
> I admit that I know little of web site programming and the libraries
> that might be available there.

A hollow voice whispers, "Kerberos".  This is exactly what it's for:
clients identifying themselves to multiple services without passing
persistent secrets (passwords) across the network *at all*.

-- 
Mark H. Wood, Lead System Programmer   [EMAIL PROTECTED]
Typically when a software vendor says that a product is "intuitive" he
means the exact opposite.

Attachment: pgpt3POiaGHXz.pgp
Description: PGP signature

---
You are currently subscribed to [email protected] as: [EMAIL PROTECTED]
To unsubscribe send email to [EMAIL PROTECTED] with the word UNSUBSCRIBE as the 
SUBJECT of the message.

Reply via email to