[Date Prev][Date Next]
Re: pwdCheckQuality and password hashing
I'm using pwdCheckQuality to enforce password quality restrictions for
the userPassword attribute. In order for this to work the password has
to be received on the server end in plain text. Which is fine. But when
OpenLDAP stores the password it stores it in plain text (base64 encoded).
Is there some overlay that will encrypt the userPassword before storing it?
Read the slapo-ppolicy(5) manpage. e.g. the ppolicy_hash_cleartext option.
-- Howard Chu
Chief Architect, Symas Corp. http://www.symas.com
Director, Highland Sun http://highlandsun.com/hyc/
Chief Architect, OpenLDAP http://www.openldap.org/project/