You are not logged in.
I've read in the post: "http://glpi-project.org/forum/viewtopic.php?id=3116" that authentication using LDAP in GLPI can be dangerous due to the fact that the browser will cache passwords in plain text as well as these being sent "weakly" over the network.
I'd like to know just how much of this holds true for the latest version of GLPI, and to what extent ( what is understood by sending password information weakly over the network, for example ). I'd also like to know if this still holds true in case you write the users login information by hand, using GLPI.
Thanks.
Offline
if you set up in GLPI your LDAP server using a LDAPS protocol, password are not sent "weakly" over the network.
There are no security problem in that case.
MoYo - Julien Dombre - Association INDEPNET
Contribute to GLPI : Support Contribute References Freshmeat
Offline
I'd also like to know if this still holds true in case you write the users login information by hand, using GLPI.
No, password are crypted in the database. We just compare md5sum.
JMD / Jean-Mathieu Doléans - Glpi-project.org - Association Indepnet
Apportez votre pierre au projet GLPI : Soutenir
Offline
But in case you use an Active Directory LDAP. Is it still secure ? And also, does the browser not cache the passwords in plain text as mentioned in the post I referenced ?
Thanks.
Offline
But in case you use an Active Directory LDAP. Is it still secure ?
As i already answer in another thread, this an administrator responsability to ensure the level of security you need for your communication with GLPI and AD. The administrator have to use SSL for example.
And also, does the browser not cache the passwords in plain text as mentioned in the post I referenced ?
Thanks.
I haven't heard about that. I think it would be interessed to have more real elements about this affirmation.
JMD / Jean-Mathieu Doléans - Glpi-project.org - Association Indepnet
Apportez votre pierre au projet GLPI : Soutenir
Offline