Hello all,
I'm working on Self-service application and want to prevent user from re-using old passwords. What is correct way to chage password takin in mind password history?
I guess it is:
1. Bind with special user and check if specified uid exists 2. Bind using user-supplied uid and password 3. Get password policy, history etc. and validate on selfservice-side 4. Execute LDAP modifyRequest with single item: userPassword and value of new hashed password.
In my case same password gives same hash. Are there any way to force encrypted password history validation on server side?
Thank you.