Caislean
Caislean copied to clipboard
Change LDAP password encryption scheme to {CRYPT} wherever possible
SSHA is salted SHA-1, which is not considered secure. slappasswd can be forced to use crypt with SHA-512 hashing both on Debian 7 and Debian 8.
Commands should be replaced (at least) in roles:
-
openldapwherever a password is generated usingslappasswd -
php-ldap-passwordwhere the password is generated using a PHP function