--
You received this message because you are subscribed to the Google Groups "Google Apps Manager" group.
To unsubscribe from this group and stop receiving emails from it, send an email to google-apps-man...@googlegroups.com.
To post to this group, send email to google-ap...@googlegroups.com.
Visit this group at https://groups.google.com/group/google-apps-manager.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/d1a05f71-6e22-424d-a6bc-2e21888efb81%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Jay Lee
If you only have the SHA-1 hash of a user's password, use a command like:gam update user m...@email.com password 5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8 sha1to send the SHA-1 hash. However, if you have the raw password, just run:gam update user m...@email.com password rawpasswordas GAM will then hash the raw password you input with the SHA-512 algorithm which is salted and more secure. The only way to get GAM to send the raw password (still over TLS so it's considered secure) is to run:gam update user m...@email.com password rawpassword nohashJay
On Mon, Jan 25, 2016 at 1:51 PM Jefferson Davis <jda...@standardschools.net> wrote:
When I attempt to do this I get an "Invalid Password" error from gam.py--./gam.py update user password {SHA}<base_64_encoded sha1 hash> shaERROR: 400: Invalid Password - invalidldapsearchWhat am I doing wrong? am I sending the hash in the wrong format?
You received this message because you are subscribed to the Google Groups "Google Apps Manager" group.
To unsubscribe from this group and stop receiving emails from it, send an email to google-apps-manager+unsub...@googlegroups.com.
To post to this group, send email to google-ap...@googlegroups.com.
Visit this group at https://groups.google.com/group/google-apps-manager.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/d1a05f71-6e22-424d-a6bc-2e21888efb81%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Jay Lee
----Jay Lee
You received this message because you are subscribed to a topic in the Google Groups "Google Apps Manager" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/google-apps-manager/xDdjRhQG8G4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to google-apps-man...@googlegroups.com.
To post to this group, send email to google-ap...@googlegroups.com.
Visit this group at https://groups.google.com/group/google-apps-manager.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/CA%2BVVBp-htqBEdcT%3DnsE5vzisNPwUmzKiU8hQWfA4Wjtwv1JdDg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
On Jan 27, 2016 10:45 AM, "Jefferson Davis" <jda...@standardschools.net> wrote:
> I have a bash one-liner that reads the attribute from ldap and returns the hex string, if you're at all interested. If you're not, my feelings will not be injured ;)
Yes, please share! I was going to write something similar.
--
You received this message because you are subscribed to the Google Groups "Google Apps Manager" group.
To unsubscribe from this group and stop receiving emails from it, send an email to google-apps-man...@googlegroups.com.
To post to this group, send email to google-ap...@googlegroups.com.
Visit this group at https://groups.google.com/group/google-apps-manager.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/CAE32uS5sVW765sF4v9hcdiwm8x2jZHMjQHq1-UebYhgaHEzVqQ%40mail.gmail.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/CABwB6%3Dc-0_Dy9V-PGevngmHQ9Bd89hRzvP1aZ-3Si-0gLBBGaw%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
Jay Lee
--
You received this message because you are subscribed to a topic in the Google Groups "Google Apps Manager" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/google-apps-manager/xDdjRhQG8G4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to google-apps-man...@googlegroups.com.
To post to this group, send email to google-ap...@googlegroups.com.
Visit this group at https://groups.google.com/group/google-apps-manager.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/CAE32uS5sVW765sF4v9hcdiwm8x2jZHMjQHq1-UebYhgaHEzVqQ%40mail.gmail.com.
--
You received this message because you are subscribed to a topic in the Google Groups "Google Apps Manager" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/google-apps-manager/xDdjRhQG8G4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to google-apps-man...@googlegroups.com.
To post to this group, send email to google-ap...@googlegroups.com.
Visit this group at https://groups.google.com/group/google-apps-manager.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/CA%2BVVBp9eu-xjoUp5vAQbge%3DBu1jeDaYYhPq1WZaq6kr43sosKw%40mail.gmail.com.
#!/bin/bash
if [ -z $1 ]
then
echo ""
echo "usage: sha_to_hex.sh <userid>"
echo ""
exit 1
fi
user=$1
DN="cn=manager,dc=standard,dc=k12,dc=ca,dc=us"
pwdfile="/opt/GAM/ldap" # Note this file cannot have any newline chars in it.
echo -n "Checking $user... "
hashed_result=$( echo -n $( ldapsearch -LLL -x "uid=$user" userPassword -D $DN -y $pwdfile | grep userPassword | sed 's/userPassword:: //' ) | base64 -d | sed 's/{SHA}//' | base64 -d | xxd -p )
echo $hashed_result--
You received this message because you are subscribed to a topic in the Google Groups "Google Apps Manager" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/google-apps-manager/xDdjRhQG8G4/unsubscribe.
To unsubscribe from this group and all its topics, send an email to google-apps-man...@googlegroups.com.
To post to this group, send email to google-ap...@googlegroups.com.
Visit this group at https://groups.google.com/group/google-apps-manager.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/CAE32uS5sVW765sF4v9hcdiwm8x2jZHMjQHq1-UebYhgaHEzVqQ%40mail.gmail.com.