Skip to main content
Question

LDAP and password encryption

  • November 27, 2018
  • 2 replies
  • 18 views

Bernard92
Forum|alt.badge.img+2

Hello,

One of our client is saying that LDAP password are transmitted unencrypted over the network when they authenticate to their Vertica servers using LDAP authentification.
What's the best way to encrypt them ?

Regards
Bernard

2 replies

DaveT
Forum|alt.badge.img
  • Participating Frequently
  • November 27, 2018

I have not tested it but I am guessing based on experience with other products in the past that is correct. Without TLS involved there is probably no hash/encrypt of the password because Vertica (or probably name your product here) is not involved in managing the password. It has to pass what the LDAP server understands. LDAP over TLS is the solution for them to allow encryption assuming LDAP is their authentication solution of choice. Of course, Vertica also supports other authentication solutions that behave differently. For example, Vertica-managed (hash) authentication would use a hashed transmission since Vertica is managing the passwords in this case.

I will let others correct me if they know that Vertica does something differently here via LDAP without TLS but I don't see how it could.


Bernard92
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • November 28, 2018

thanks - I'll ask the customer to investigate LDAP over TLS