[jadmin] Re: jabberd14 'crypt' password storage in postgressql

Oliver Block lists at block-online.eu
Thu Jun 14 09:16:17 CDT 2007


Am Donnerstag, 14. Juni 2007 14:28 schrieb Simon Wilkinson:

> The fundamental fact is that for the vast majority of today's
> authentication technologies, including ones that are mandatory to
> implement in XMPP, the server will require access to the plaintext
> version of the secret.

How about sasl based on pam?

> If you're still unclear, then Bruce Schneier's "Applied 
> Cryptography" is a highly recommended read.
I am reading 'Secure Programming Cookbook for C and C++' from Viega and 
Messier, at the moment because I need something close to a programming 
language.

Regards,

Oliver



More information about the JAdmin mailing list