Entourage / Exchange / LDAP -- sending password in clear text?

B

Bill Dennen

Some background:

I am using Entourage to connect to our Exchange server. Mail and
calendar work fine.

For directory services, I am using our company's regular LDAP server.
This server does not require login or SSL. It uses port 389.

Connection to mail server is over SSL.

A couple of issues:

1) LDAP searches do not work. When I do attempt to do an LDAP search,
Entourage send my username and password in clear text to the LDAP
server (even though I have configured Entourage to not authenticate).

I verified this using tcpflow.

!!! Seems like a bug and a security hole.

2) I can add another LDAP entry to the Directory Servers, using the
same info as in the Exchange entry, and it works fine (no password is
sent over the wire.

Any ideas? I am most concerned about #1 because this is a security
problem. I'm not sure why Entourage is even sending the password,
because I have configured it to not log in.

Thanks-
Bill
 
B

Bill Dennen

1) LDAP searches do not work. When I do attempt to do an LDAP search,
Entourage send my username and password in clear text to the LDAP
server (even though I have configured Entourage to not authenticate).

I verified this using tcpflow.

!!! Seems like a bug and a security hole.

I re-checked. There is no way to telll Entourage *not* to authenticate
in this configuration. That is, when adding Directory Services via an
Exchange account. So, it always authenticates, using the
username/password you provide for the IMAP portion of the account.

(Our company has a separate LDAP server and does not allow searching
of the GAL via LDAP...)

-Bill
 
M

Mickey Stevens

I re-checked. There is no way to telll Entourage *not* to authenticate
in this configuration. That is, when adding Directory Services via an
Exchange account. So, it always authenticates, using the
username/password you provide for the IMAP portion of the account.

(Our company has a separate LDAP server and does not allow searching
of the GAL via LDAP...)

That's a known problem, but it is possible to get around it. See Note #16
on the Exchange Server page of The Entourage Help Page for instructions on
how to configure your Exchange account so that it does not send
authentication when contacting the LDAP server.
<http://www.entourage.mvps.org/faq/exchange_server.html#Anchor-exupnotes>
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top