[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: Copying SSHA userPassword from Oracle to OpenLDAP
- To: Nicholas Carl <ncarl.personal@gmail.com>
- Subject: Re: Copying SSHA userPassword from Oracle to OpenLDAP
- From: Lucio De Re <lucio.dere@gmail.com>
- Date: Wed, 23 Jan 2019 06:15:47 +0200
- Cc: openldap-technical@openldap.org
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=wKj2i3sRIeaRWu4x7Ol200SfFKrQQJM4XFEBV5E+w2k=; b=GL2mY4XcbMIakHRnMhWiuBb6xtbQc79H8pAu9Z0ndzz2DGQhM0b7ZTf5HriXsF/5io ItXZKPcOpoSFuM5kNMmT7rvY/iDLbw/XR0PhNIMGA7zZj2FMFp9p70gnk1pKqsib3aeg xVAuKJO67KG368wyRjn38672M2jWzjhSW7Cg3WXQWZz/JYhFI8h7XVuMwVRk0kcJRC2+ 1VSoPf89hE9j9QRrgA9b7TjPqRir5uGYYXcs+EV36nafe6W8ZLC6L+lrIR0t+8N/Co4m nfSac+Q9o1pDcgoZPiYCmi9csUCds7+D4altA0YYxLBW0+x0JfrDwwgTO6dHmfBp5Qx1 ugwA==
- In-reply-to: <CAAkpD4OEpXGJoGQ1at_x358D10aj=0Xx4dX-hLp185TwpHeyhg@mail.gmail.com>
- References: <CAAkpD4OEpXGJoGQ1at_x358D10aj=0Xx4dX-hLp185TwpHeyhg@mail.gmail.com>
On 1/22/19, Nicholas Carl <ncarl.personal@gmail.com> wrote:
>
> # Querying other LDAP server
>
> $ ldapsearch -h oracleServer -D - -w - -b - "uid=-" | grep ^userPassword
>
> userPassword::
> e1NTSEF9S3hNQVVoRGY0Y0ZMVXdVREZQb1VDMFNvRFdRb0c2TnNLRTVZUWc9PQ=
>
> $ ldapsearch -h oracleServer -D - -w - -b - "uid=-" | grep ^userPassword |
> base64 -d
>
> {SSHA}KxMAUhDf4cFLUwUDFPoUC0SoDWQoG6NsKE5YQg==base64: invalid input
>
>
> ## After importing decrypted into new server, the encrypted string matches.
>
> $ ldapsearch -h openLDAPServer -D - -w - "uid=-" | grep ^userPassword
>
> userPassword::
> e1NTSEF9S3hNQVVoRGY0Y0ZMVXdVREZQb1VDMFNvRFdRb0c2TnNLRTVZUWc9PQ=
>
I also get an invalid input. Little wonder it doesn't work:
$ echo 'e1NTSEF9S3hNQVVoRGY0Y0ZMVXdVREZQb1VDMFNvRFdRb0c2TnNLRTVZUWc9PQ='
| base64 -d
{SSHA}KxMAUhDf4cFLUwUDFPoUC0SoDWQoG6NsKE5YQg==base64: invalid input
It's not what you want, is it?
$ echo '{SSHA}KxMAUhDf4cFLUwUDFPoUC0SoDWQoG6NsKE5YQg==' | base64
e1NTSEF9S3hNQVVoRGY0Y0ZMVXdVREZQb1VDMFNvRFdRb0c2TnNLRTVZUWc9PQo=
Was that "o" near the end a cut-n-paste error?
--
Lucio De Re