Purpose of LDAP Hide Passwords set to No

Re: Purpose of LDAP Hide Passwords set to No

by Iñaki Arenaza -
Number of replies: 0
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers
I'm afraid the LDAP auth plugin doesn't use the locally saved passwords (if you have Hide Passwords set to no) at all. I can't tell you what's the purpose of having a local copy (I wasn't there when the original author of the plugin created it), but I know for sure that the local copy has never been used.

With respect to using them as a temporary failover option, that would be technically possible. It would make the code a bit more fragile (as it would depend on other parts of Moodle) and a bit more complex, but should certainly be doable.

On the other hand, the admin would need to be aware of the possible consequences of enabling this. If Moodle can't contact the LDAP servers, it can't be sure the account is still available, or if it's locked/disabled, or the password has changed (or the user is forced to change it), etc. So this could be used to log into Moodle when the user shouldn't be let in (which depending on the situation/organization can be a huge security problem!)

Saludos.
Iñaki.

Average of ratings: Useful (1)