| | |
| | | ! CDDL HEADER END |
| | | ! |
| | | ! |
| | | ! Portions Copyright 2007 Sun Microsystems, Inc. |
| | | ! Portions Copyright 2007-2008 Sun Microsystems, Inc. |
| | | ! --> |
| | | <adm:managed-object name="crypt-password-storage-scheme" |
| | | plural-name="crypt-password-storage-schemes" |
| | |
| | | </adm:synopsis> |
| | | <adm:description> |
| | | This implementation contains only an implementation for the user |
| | | password syntax, with a storage scheme name of "CRYPT". |
| | | password syntax, with a storage scheme name of "CRYPT". Even though it |
| | | is a one-way digest, the |
| | | <adm:user-friendly-name /> |
| | | is relatively weak by today's standards. Because it supports |
| | | only a 12-bit salt (meaning that there are only 4096 possible ways to |
| | | encode a given password), it is also vulnerable to dictionary attacks. |
| | | You should therefore use this storage scheme only in cases where an |
| | | external application expects to retrieve the password and verify it |
| | | outside of the directory, rather than by performing an LDAP bind. |
| | | </adm:description> |
| | | <adm:profile name="ldap"> |
| | | <ldap:object-class> |