Question : LDAP Security

Since LDAP is an unsecured protocol, does that mean that the username and password are sent in plain text when a user logs into windows computer in an Active Directory environment.  I saw that there was an option to make LDAP go over SSL.  Could someone enlighten me on this whole topic please.

Answer : LDAP Security


Sure, if you were in a position to watch the traffic and simple (LDAP) authentication were used. It's why basic LDAP authentication should only be permitted over a secure network or with encryption.

You have applications using that now which you are concerned about?

Chris
Random Solutions  
 
programming4us programming4us