Re: bug in rlm_ldap authorization password handling?

2009-11-17 Thread Alan DeKok
John Dennis wrote: Authentication modules need access to either the cleartext password or hashed password, it is the role of the authorization modules to insert the password information into the *config* list of the request. The authentication modules will extract the password information from

bug in rlm_ldap authorization password handling?

2009-11-16 Thread John Dennis
I'm a little confused by how rlm_ldap is handing passwords. First let me state what I believe to be true, if I'm wrong on any of these assumptions please correct me. Authentication modules need access to either the cleartext password or hashed password, it is the role of the authorization

Re: bug in rlm_ldap authorization password handling?

2009-11-16 Thread tnt
I'm a little confused by how rlm_ldap is handing passwords. First let me state what I believe to be true, if I'm wrong on any of these assumptions please correct me. They are, sort of, correct. Or am I just missing something? You are looking at rlm_ldap in isolation. rlm_pap will handle