Request
Add a native option in Active Roles Synchronization Service to select the password hashing algorithm used when synchronizing passwords to OpenLDAP.
Business Need
Organizations synchronizing Active Directory accounts and passwords to OpenLDAP may require a specific password storage format based on their existing OpenLDAP configuration, application compatibility, or internal standards.
Currently, Active Roles Synchronization Service does not provide a built-in setting to select the hashing algorithm. The resulting password format is controlled by the OpenLDAP environment. Although a PowerShell password-transformation script may be used, this requires custom development and ongoing maintenance.
Requested Functionality
Provide a configurable setting within an OpenLDAP password synchronization rule that allows administrators to:
userPassword attribute.An enhancement request (731950) has been created detailing the feature above.
STATUS
The product team will evaluate the request and this feature may become available on a future release of the product.
Please refer to this article for updates or contact support referencing the Enhancement Request ID: 731950.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center