I’m back from vacation, relaxed and tanned. This year, my wife and I
have dedicated our time to our family and parents. And I’ve had my
yearly overdose of novels and books (from Harry Potter 6 to Confusius).
Coming back to work is always a mix of pleasure and pain. On one side,
it’s good to reactivate the neurones, and on the other one, the first
task is to clean up the huge amount of emails that have kept on
stacking in the mailbox. This done, I’m back full speed on the
Directory Server and the Identity business.
I’ve just noticed today that my friend and fellow Michael Haines has started a blog.
Michael’s title is certainly not “Mister Solaris LDAP” but he is the author of two best sellers of the Sun BluePrints series:
(both books that I had participated in) and he has a huge experience in deploying LDAP (and Sun Java
System Directory Server) as a naming service in the enterprises.
My summer vacations are starting now and I’ll be avoiding keyboards and screen for a while…
Expect this place to be silent until the end of the month.
This week I was in Paris for the 63rd IETF meeting.
Though I mainly go to the IETF to work on LDAP (both with the LDAPBis working
group and as an individual contributor -for example with the LDAP
password policy- ), I often go to other working groups and BOF sessions
to get a sense of what’s going on in the Internet community (at least
in the areas that I understand).
And this time, the buz was clearly around the recent vulnerabilities
with the use of one-way hash functions such as MD5 and SHA1. With the
increasing computation power of computers and the ease of deployment of
man-in-the-middle attack, these functions are no longer considered as
secure enough. And so are authentication mechanisms based on cleartext
challenge-response exchanges. For Directory Server’s customers, this
means that the way to secure their authentication t0 LDAP is to use TLS
either via the use of StartTLS extended operation or LDAP over SSL.
Once the connection is secured, the authention could be based on the
Simple bind, Sasl Bind with Digest-MD5 mechanism or with exchanged
On the LDAP front, the participation is diminishing (mainly remains
Novell, OpenLDAP and Sun) but the work of revising the LDAPv3
specification for clarification and better interoperability is mainly
done. The last remaining issues were hammered this week (hopefully) and
we are expecting RFC publication before or around next IETF meeting.
LDAPers in IETF action: Roger, Kurt, Jim and Ludo (left to right).
Tags: LDAP IETF Directory Server