RE: SASL secrets in LDAP

>    >For many good reasons, we discourage the storage of plaintext
> passwords in
>    >LDAP.
>    Yes, but if userPassword is plaintext (as it really should be, see
>    RFC 2256), then we can certainly use it for DIGEST-MD5.
> Also, remember that the DIGEST-MD5 password hash is sufficient for
> authentication (it is not a one-way hash like /etc/passwd).

Good points. OK, sounds like generating the hash is a lot of unnecessary
effort since it needs as much protection as the plaintext. Might as well
just use the userPassword attribute as-is then. Simplifies life

