LDAP authentication security ?



Hi,
(First, sorry for my english ;-))

I would like to use an LDAP authentication with my application (Quality Center). So, the user will have to type his Active Directory username and password BUT the LDAP authentication secured is it secured ?

By default, there is no encryption so the password is transmitted in clear text ?

Do I need to use LDAP Over SSL ?
What is SASL ?

Thank you

--
Pascal


.