[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freeradius-users
Subject:    Re: CentOS OpenLDAP pwdReset Attribute
From:       Alan DeKok <aland () deployingradius ! com>
Date:       2021-10-26 21:07:19
Message-ID: 935D027E-289B-4D4E-842D-1135187B7047 () deployingradius ! com
[Download RAW message or body]

On Oct 26, 2021, at 3:28 PM, Marek Zarychta <zarychtam@plan-b.pwste.edu.pl> wrote:
> Thank you for the comprehensive explanation, but I still believe that
> MD4 hash is more GDPR conformant than Cleartext-Password ;)

  Only because it's *slightly* better than clear-text passwords, and because the \
political / legal rules have little relation to the reality of computer security.

> But can anything besides NTPassword or Cleartext-Password work for
> MSCHAP authentication?

  No.

  We're stuck with decisions made in the late 1980s.

  Alan DeKok.


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic