LDAP Password Hash
Description
Password hash plugin supporting password hashes commonly used by LDAP servers. The syntax is {hash-func}hash-value, where hash-func is the hash function identifier and hash-value is the base64-encoded hash value and salt.
This plugin has been tested with OpenLDAP and 389 Directory Server LDAP implementations.
Currently supported hash functions are:
- SSHA: Salted SHA-1
- SSHA256: Salted SHA-256
- SSHA384: Salted SHA-384
- SSHA512: Salted SHA-512
The use of this plugin is discouraged due to security reasons. We recommend using this hash for migration purposes or compatibility with an existing LDAP only. Please use "Argon2id Password Hash" instead.
May be used by
TAN Batch Task History Password Hash Adminapp REST API Configuration Persister Password Service Persister Password Service Default Password Repository Default Password Repository Basic Secret Question Settings Administrators Management Token IAK Handler Secret Questions Settings External Database Password Repository External Database Password Repository Credential Secret Generator Persister IAK Verifier Matrix Card Generator Default TAN Service Encrypted Password Hash Combined Password Hash Combined Password Hash Credential Data mTAN Handler Fixed TAN Generator Task AWS KMS Password Hash
Properties
Generation Hash Function (
generationHashFunction) Description
The hash function used to generate password hashes.
Attributes
Enum
Mandatory
Salt Length (
saltLength) Description
The length of the salt (in bytes) used when generating hashes.
Attributes
Integer
Optional
Default value
32
YAML Template (with default values)
type: LdapPasswordHash
id: LdapPasswordHash-xxxxxx
displayName:
comment:
properties:
generationHashFunction:
saltLength: 32