← Back to plugin index

LDAP Password Hash

Description

Password hash plugin supporting password hashes commonly used by LDAP servers. The syntax is {hash-func}hash-value, where hash-func is the hash function identifier and hash-value is the base64-encoded hash value and salt.

This plugin has been tested with OpenLDAP and 389 Directory Server LDAP implementations.

Currently supported hash functions are:

  • SSHA: Salted SHA-1
  • SSHA256: Salted SHA-256
  • SSHA384: Salted SHA-384
  • SSHA512: Salted SHA-512

The use of this plugin is discouraged due to security reasons. We recommend using this hash for migration purposes or compatibility with an existing LDAP only. Please use "Argon2id Password Hash" instead.

Type name
LdapPasswordHash
Class
com.airlock.iam.core.misc.util.password.hash.LdapPasswordHash
May be used by
Properties
Generation Hash Function (generationHashFunction)
Description
The hash function used to generate password hashes.
Attributes
Enum
Mandatory
Salt Length (saltLength)
Description
The length of the salt (in bytes) used when generating hashes.
Attributes
Integer
Optional
Default value
32
YAML Template (with default values)

type: LdapPasswordHash
id: LdapPasswordHash-xxxxxx
displayName: 
comment: 
properties:
  generationHashFunction:
  saltLength: 32