Skip to content

OpenLDAP Quick Tips: Creating encrypted passwords

OpenLDAPOpen SourceSuretec Hi All,

Here's my 6th tip in the "OpenLDAP Quick Tips" series:

"You want to encrypt the passwords that are stored in your directory server":

Previously we covered slaptest, so the next one we will cover in the slap* set of command lines tools is slappasswd

To create an encrypted password for a password "testing", we do:

CODE:
[root@suretec ~]# slappasswd  New password:  Re-enter new password:  {SSHA}4Q/jfwS2oPJtQDq7bmHozKOWkgDJNLEb


The default is SSHA encryption, which is the recommended. You can also generate a random password with the -g option:

CODE:
[ghenry@suretec ~]$ /usr/local/sbin/slappasswd -g t5e7xEJE


Thanks,

Gavin.

If you have an entry for our "OpenLDAP Quick Tips" series, why not e-mail your tip to us.

P.S. For direct access to this section, you can click OpenLDAP Quick Tips.

Trackbacks

The Suretec Blog on : OpenLDAP Quick Tips: Switch to the dynamic config backend (cn=config)

Show preview
Hi All, Here's my 12th tip in the "OpenLDAP Quick Tips" series: "You want to switch from slapd.conf to the configuration backend to slapd": The config backend is backward compatible with the older slapd.conf(5) file but provides

The Suretec Blog on : OpenLDAP Quick Tips: Switch to the dynamic config backend (cn=config)

Show preview
Hi All, Here's my 12th tip in the "OpenLDAP Quick Tips" series: "You want to switch from slapd.conf to the configuration backend to slapd": The config backend is backward compatible with the older slapd.conf(5) file but provides

Comments

Display comments as Linear | Threaded

steve on :

*I discovered a picture password site at www.pixelock.com, it seems to solve the eternal secure vs remember-able password conundrum. I have used it for the past 6 months with great success. Anyone else have a comment on this sites offering?

Cheers
Steve

Gavin Henry on :

*Hi Steve,

Looks good, but how would that integrate server side?

Anonymous on :

*Hi Gavin, once the password is generated or regenerated, it is simply copied and pasted into the the user site as required. I have also heard that Pixelock Lite is about to be launched, this is a completely anonymous Pixelock offering. I am not sure how it works yet, but I will keep an eye out for it.

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.
BBCode format allowed
Pavatar, Gravatar, Favatar, MyBlogLog, Pavatar author images supported.
Form options

Warning: Use of undefined constant CHARSET_NATIVE - assumed 'CHARSET_NATIVE' (this will throw an Error in a future version of PHP) in /home/suretecsystems/www/blog/serendipity_config.inc.php on line 182
tweetbackcheck