Re: Strong password checks

Graham Leggett <[email protected]> Sat, 29 Jan 2005 13:43:20 +0200
Newsgroups gmane.network.directoryadmin
Message-ID <[email protected]>
Mike Jackson wrote:

>> Most DSAs include modules or overlays to enforce password
>> strength/policy,  including OpenLDAP.  This should be up to the DSA.

> There is nothing in RFC 2251 about password complexity, which means that 
> if we support it then we support it in a different way for every 
> directory server. It is not transparent.

As I understood the original question, password complexity meant 
distinguishing between "hUjd63*kg" (good) and "passw0rd" (bad), and 
rejecting the password based on the admin's chosen policy.

Optionally linking DA to cracklib should do the trick.

Regards,
Graham
--
smime.p7s (application/x-pkcs7-signature, 3.1 KB) - not displayed