Nalin Dahyabhai wrote:
How do you plan to intercept the plain text password in IPA? We aren't in control of the services a user is likely to issue a SASL/PLAIN bind to are we?Would it be useful to also intercept the password used when a simple or SASL/PLAIN bind requests succeed, and take the opportunity to generate the hashes so that we can avoid forcing password changes?
-- John Dennis <jdennis redhat com>