works reasonably well, still requires manual tweak in the DB for (*& plain passwd