[CPS-devel] Re: SSHA encryption in LDAP Backing Directory

Olivier Grisel ogrisel at nuxeo.com
Wed Mar 29 10:40:59 CEST 2006


Georges Racinet a écrit :

> More encryption schemes can be implemented upon request (especially if 
> you provide an encryption function).

I think md5 would be nice too and it's in the standard library :

http://docs.python.org/lib/module-md5.html

Other hash functions might require external dependencies.

> Also worth of notice: all attempts to fetch the user's password from CPS 
> will return an empty string. This is primarily to ensure protection 
> against loops of rehashing that could corrupt your user database, but we 
> believe it's a good thing in itself.
> A side effect is that empty passwords are banned.

Empty password where already banned with LDAP before since some server switch 
automatically to the anonymous mode when you don't provide a password, even with 
a non-empty login field.

-- 
Olivier



More information about the cps-devel mailing list
More information about CPS: CPS project - CVS - API

Hosting: Nuxeo: Zope service provider


This list archive provided by Nuxeo, the leaders of open source ECM. Check out the Nuxeo 5 open source, standards-based ECM project.