RE: Sync-reg / FXA : Active Directory authentication

2014-07-04 Thread robin.aleman
ation & Support EQUANT France - Sophia Antipolis +00 33 4 92 96 64 48 robin.ale...@orange.com -Original Message- From: Ryan Kelly [mailto:rfke...@mozilla.com] Sent: Friday, July 04, 2014 01:38 To: sync-dev@mozilla.org; ALEMAN Robin SCE/ID ITS Subject: Re: Sync-reg / FXA : Active Directory

RE: Sync-reg / FXA : Active Directory authentication

2014-07-04 Thread robin.aleman
.com -Original Message- From: Richard Newman [mailto:rnew...@mozilla.com] Sent: Thursday, July 03, 2014 19:19 To: ALEMAN Robin SCE/ID ITS Cc: sync-dev@mozilla.org Subject: Re: Sync-reg / FXA : Active Directory authentication > The goal would be to at least allow users to have one password f

Re: Sync-reg / FXA : Active Directory authentication

2014-07-03 Thread Ryan Kelly
On 4/07/2014 3:18 AM, Richard Newman wrote: >> The goal would be to at least allow users to have one password for Sync & >> AD. > > If your directory service knows the user password, or even a weak hash of it, > then by definition that's a non-goal, because it would defeat Sync's ability > to

Re: Sync-reg / FXA : Active Directory authentication

2014-07-03 Thread Richard Newman
> The goal would be to at least allow users to have one password for Sync & AD. If your directory service knows the user password, or even a weak hash of it, then by definition that's a non-goal, because it would defeat Sync's ability to do end-to-end encryption. If your directory service does

Sync-reg / FXA : Active Directory authentication

2014-07-03 Thread robin.aleman
Ok you answer my question about SSO, as we guess ... it's impossible, except to create our own branch of FF/Fennec. Hum maybe an idea for the far far future : - add an "about:config" parameters for FXA/Sync-storage customs servers - Sync client and FXA check the network.negotiate-auth.trusted-ur