In this post we will see how we can reset password for our OpenLDAP users using the special utility ldappasswd.
Change user password using admin credentials.
When it comes to resetting user passwords, one of the most common things is to reset user’s password providing our admin credentials. Let’s change the password for the user with DN cn=Orkhan Sadigov,ou=users,dc=geekstuff,dc=org. The following command will reset user’s password using cn=admin,dc=geekstuff,dc=org as Bind DN:
Users can also reset their passwords themselves. To do this they have to specify their old password, new password and DN. Admin credentials are NOT required in this case. The following command will change password for user with DN cn=Orkhan Sadigov,ou=users,dc=geekstuff,dc=org :
Another way to change the password is to use ldapmodify utility. This utility allows to modify LDAP entries by providing new values for any attributes in LDIF format. As user password is just another attribute it is possible to set a new password using ldapmodify.
First, let’s create an LDIF file set_pass.ldif specifying which entry and which attributes we want to modify. The file should look like this:
The first line specifies which entry we want to modify. The next line changetype: modify indicates that we want to modify the entry( we can also delete the entry if use changetype: delete). The line replace: userPassword is used to indicate that we are going to change the value of attribute userPassword. The final line sets the actual value of the attribute userPassword to new_password.
Now let’s import that data by running ldapmodify command: