mirror of
https://git.openldap.org/openldap/openldap.git
synced 2025-12-23 08:09:34 -05:00
Add description of {K5KEY} password mech
This commit is contained in:
parent
aa913f1bef
commit
d74f40b650
1 changed files with 7 additions and 2 deletions
|
|
@ -1,4 +1,4 @@
|
||||||
Copyright 2004 Howard Chu, Symas Corp. All rights reserved.
|
Copyright 2004-2005 Howard Chu, Symas Corp. All rights reserved.
|
||||||
|
|
||||||
Redistribution and use in source and binary forms, with or without
|
Redistribution and use in source and binary forms, with or without
|
||||||
modification, are permitted only as authorized by the OpenLDAP
|
modification, are permitted only as authorized by the OpenLDAP
|
||||||
|
|
@ -15,7 +15,12 @@ password hashes for an LDAP user.
|
||||||
The Kerberos support is written for Heimdal using its hdb-ldap backend.
|
The Kerberos support is written for Heimdal using its hdb-ldap backend.
|
||||||
If a PasswordModify is performed on an entry that has the krb5KDCEntry
|
If a PasswordModify is performed on an entry that has the krb5KDCEntry
|
||||||
objectclass, then the krb5Key and krb5KeyVersionNumber will be updated
|
objectclass, then the krb5Key and krb5KeyVersionNumber will be updated
|
||||||
using the new password in the PasswordModify request.
|
using the new password in the PasswordModify request. Additionally, a
|
||||||
|
new "{K5KEY}" password hash mechanism is provided. krb5KDCEntries that
|
||||||
|
have this hash specifier in their userPassword attribute, Simple Binds
|
||||||
|
will be checked against the Kerberos keys of the Entry. No data is
|
||||||
|
needed after the "{K5KEY}" hash specifier in the userPassword, it is
|
||||||
|
looked up from the Entry directly.
|
||||||
|
|
||||||
The Samba support is written using the Samba 3.0 LDAP schema. If a
|
The Samba support is written using the Samba 3.0 LDAP schema. If a
|
||||||
PasswordModify is performed on an entry that has the sambaSamAccount
|
PasswordModify is performed on an entry that has the sambaSamAccount
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue