November 2017
Intermediate to advanced
542 pages
14h 24m
English
Now that you know a bit about how LDAP uses passwords, and we have PasswordComparisonAuthenticator set up, what do you think will happen if you log in using our sshauser@example.com user with their password, stored in the SSHA format?
Go ahead, put the book aside and try it, and then come back.
Your login was denied, right? And yet you were still able to log in as the user with the SHA-encoded password. Why? The password encoding and storage didn't matter when we were using bind authentication. Why do you think that is?
The reason it didn't matter with bind authentication was that the LDAP server was taking care of the authentication and validation of the user's password. With password ...
Read now
Unlock full access