new unicode_password ldb module

Luke Howard lukeh at
Wed Dec 28 07:59:05 GMT 2005

>By ensuring that the krb5key attribute is the only one we need to
>retrieve, this also simplifies the run-time KDC logic.  (The each value
>of the multi-valued attribute is encoded as a 'Key' in ASN.1).

FWIW, Active Directory uses three attributes to store keys: dBCSPwd
(the LM hash), unicodePwd (the NT hash), and supplementalCredentials
(everything else).


-- Luke


More information about the samba-technical mailing list