Thanks for your help all. it looks like CRYPT was the problem. I've changed passwords over to SSHA and everything works as designed. -Aaron From: El?as Halld?r ?g?stsson <elias at hi.is<mailto:elias at hi.is>> Date: April 26, 2010 6:18:45 PM MDT To: "389-users at lists.fedoraproject.org<mailto:389-users at lists.fedoraproject.org>" <389-users at lists.fedoraproject.org<mailto:389-users at lists.fedoraproject.org>> Subject: Re: Entire password not checked Reply-To: General discussion list for the 389 Directory server project. <389-users at lists.fedoraproject.org<mailto:389-users at lists.fedoraproject.org>> Aaron Mills skrifa?i: However, whenever users authenticate via LDAP the server appears to check only the first 8 characters of their passwords. You're probably using the CRYPT password method. Other, newer and safer methods, such as SSHA, can store much longer passwords. <Digest Footer.txt> Aaron Mills Systems Administrator Return Path, Inc. aaron.mills at returnpath.net<mailto:aaron.mills at returnpath.net> -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.fedoraproject.org/pipermail/389-users/attachments/20100427/0e4fa92b/attachment.html