In general, I would be surprised if this were possible. SHA2 is not an encryption, it is a hash - an entirely different proposition.

On May 18, 2009, at 5:52 AM, Mikael Kermorgant wrote:

Hello,

I'd like to know if it is possible to encrypt a user's password in Active Directory's format, and then import it into this user's Active Directory account ?

Given our particular situation, we probably won't be able to interconnect the central ldap unix server nor the specific application used for managing our accounts. Therefore, we're studying the solution to create the accounts in active directory and syncing passwords in one way only, by receiving it already encrypted and ready for import.


Management application for account creation --> Central unix ldap server with password encrypted in SHA2
             |
             |
             |
             v
  Active Directory


Do you know it that is possible ?
Aren't there some difficulties with AD's encryption format ? (is it open ?)

From what I've read (http://support.microsoft.com/default.aspx?scid=kb;EN-US;269190 ), my wish is not listed as a solution but maybe someone here can confirm it's impossible ?

Regards,

--
Mikael Kermorgant

Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to