hi.. just wondering how i could compare the password that user key-in with the one in the LDAP server before i let the application update the password for the user, as i found out that the password i retrieve using cfa_userGet is encrypted but the password which user key-in in form field is in plain text. any advise? ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Structure your ColdFusion code with Fusebox. Get the official book at http://www.fusionauthority.com/bkinfo.cfm FAQ: http://www.thenetprofits.co.uk/coldfusion/faq Archives: http://www.mail-archive.com/cf-talk@houseoffusion.com/ Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists