OpenLDAP currently implements Draft 7 of the "Password Policy for LDAP Directories" specification. This spec defines schema and mechanisms for managing password expiration, failed login attempts, password quality checks, and various other password policy features. The password policy support is implemented on the server as an overlay, with some ancillary support in libldap for client processing.

The password policy overlay is fully documented in the slapo-ppolicy(5) manpage.

This overlay is bundled in the OpenLDAP 2.3 release; it is not included in OpenLDAP 2.2 but the code may be obtained from CVS and used in 2.2 if desired.

