Since SSHA-1 is weak these days I'd like to switch to PBKDF2, Bcrypt or the 
like with key stretching. Since Openldap does not support relatively strong 
hashes, do you guys use SASL to store stronger hashes? If so, what kind of 
backend are you using to store hashes?

Background:
OclHashcat can generate tens of billions of SHA-1 hashes per second with 
off-the-shelf hardware. But it can only generate thousands of bcrypt hashes per 
second on similar hadware: https://hashcat.net/forum/thread-1541.html .

Reply via email to