RE: Question about openldap admin's guide

> Hello,
> In the OpenLDAP 2.2 Admin Guide, it is stated as
> follows:
> "To use secrets stored in the LDAP directory, place
> plaintext passwords in the userPassword attribute"

That text is specifically in the section regarding SASL authentication.
> Just wondering...
> can we use encrypted password, like:
> userPassword        {SHA}wektalskgjlaksfgjlf  ??

Not with strong SASL authentication.

> If we can only use plaintext password, then what's the
> purpose of password-hash in the slapd.conf ?

You can only use the hashed passwords for Simple Binds.

  -- Howard Chu
