password compare or attribute matching on search via ldap


hello.

is there recommended way perform password verification on either ldap search or ldap compare command.

i thought using userpassword or unicodepwd attributes on user object both not set.

can set match password provided on user creation or update , can used verify password provided via ldap.

note. bind credentials using different dedicated user.  , want verify different user , password .

can work via search filter or compare operations?

thank you.

hi moorenut,

based on understanding, want use ldap search or ldap compare command verify user's password using user account, feel free correct me if misunderstood.

generally, passwords encrypted storing in ad database, can not query plaintext of password of user, administrator can't see it.

in gpo, there setting, "store passwords using reversible encryption", means password can reversed ciphertext plaintext dedicated algorithms, while the police is highly not suggested enabled. , seems applied specific applications need use password of users, think application may have process decrypt ciphertext inside. so, don't know how can account decrypt password of account.

store passwords using reversible encryption:

https://technet.microsoft.com/en-us/library/hh994559(v=ws.11).aspx

best regards,

anne


please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.




Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client