Specifications

42 Chapter 3 User Authentication With Open Directory
LDAP Bind Authentication
For user accounts that reside in an LDAP directory on a non-Apple server, Open
Directory attempts to use simple LDAP bind authentication. Open Directory sends the
LDAP directory server the name and password supplied by the authenticating user. If
the LDAP server finds a matching user record and password, authentication succeeds.
Simple LDAP bind authentication is inherently insecure because it transmits clear text
passwords over the network. But you can secure simple LDAP bind authentication by
setting up access to the LDAP directory via the Secure Sockets Layer (SSL) protocol. SSL
makes access secure by encrypting all communications with the LDAP directory.
LL2352.Book Page 42 Friday, August 22, 2003 3:12 PM