Hello all,

I'm working on Self-service application and want to prevent user from re-using old passwords. What is correct way to chage password takin in mind password history?

I guess it is:

1. Bind with special user and check if specified uid exists
2. Bind using user-supplied uid and password
3. Get password policy, history etc. and  validate on selfservice-side
4. Execute LDAP modifyRequest with single item: userPassword and value of new hashed password.

In my case same password gives same hash. Are there any way to force encrypted password history validation on server side?

Thank you.

