From: James Yang Date: 2007-08-23T22:41:38+09:00 Subject: Re: MD5 authentication against Active Directory with ruby ld Thanks. next question is how to encrypt the network connection with AD for binding process. Here is the result for ldapsearch. ----------------------------------------------------------------------- ldapsearch -h AD -p 389 -x -b "" -s base -LLL supportedSASLMechanisms dn: supportedSASLMechanisms: GSSAPI supportedSASLMechanisms: GSS-SPNEGO supportedSASLMechanisms: EXTERNAL supportedSASLMechanisms: DIGEST-MD5 Francis Cianfrocca wrote: > On 8/22/07, James Yang wrote: >> >> It is still confusing to me. I wonder if it is true that a plaintext >> password would be transfered over the network in the case that we use >> the plaintext password to bind with AD. If this is correct, there is no >> security. I guess there should be an efficient way to work it out. > > > > Yes, the plaintext psw is transferred over the network, whether the > plaintext is some readable passphrase or an MD5 (or other) hash. Use > encryption for the network connection. -- Posted via http://www.ruby-forum.com/.