Uploaded image for project: 'Directory ApacheDS'
  1. Directory ApacheDS
  2. DIRSERVER-2179

Password hashing interceptor - password history entries are not hashed

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • hash interceptor, ppolicy
    • None

    Description

      Hi.

      In order to use the server-side password policy validation - we have to pass the passwords as plaintext and not hashed by the client.

      Password hashing interceptor hashes the passwords according to the configuration, BUT - the new added pwdHistory entry will contain the plaintext value of the password.

      Is there any way to have the password policy validation on the server and the hashed password to be saved in the history at the same time?

      Thanks

      Attachments

        Activity

          People

            Unassigned Unassigned
            dmitrysm2000 Dmitry Smeliansky
            Votes:
            1 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated: