-
Suggestion
-
Resolution: Done
Hello everyone,
We’re happy to inform you that we’ve released Crowd 4.2 which encrypts all passwords to external systems that are stored in the Crowd’s database. These are:
- Passwords that allows Crowd to connect to LDAP / AD directory
- Remote Crowd directory application passwords
- Azure AD web application keys
- SMTP mail passwords
- Proxy passwords
We’d like to emphasize that the encryption of application.password stored in crowd.properties file which is used by clients connecting to Crowd is not in the scope of this ticket. This suggestion is tracked in another ticket: CWD-5649.
Best regards,
Crowd team
Anywhere that a password is stored in plaintext in Crowd's database, it should be encrypted. This will not stop a knowledgeable attacker, but may slow them down.
- blocks
-
JRASERVER-38609 Crowd User Directory application password stored in plain text
- Closed
- incorporates
-
CWD-1434 Don't store the SMTP Server password in clear text
- Closed
- is duplicated by
-
CWD-2200 LDAP directory user DN password
- Closed
-
CWD-2838 crowd.properties password entry in plain text
- Closed
-
CWD-3841 Mail Server Password Should be Encrypted in The Database
- Closed
- relates to
-
BSERV-4819 Stash uses plain text passwords in the database for the Crowd User Directory
- Closed
-
JRASERVER-72470 Jira stalls due to contention on CachedEncryptor.decrypt
- Closed
-
JRASERVER-45612 Active Directory/LDAP credentials stored in database in cleartext
- Closed
-
CONFSERVER-31605 LDAP and Active Directory credentials are stored in plain text in database
- Closed
-
CONFCLOUD-31605 LDAP credentials are stored in plain text in database
- Closed
-
LEM-359 Loading...
- is cloned by
-
KRAK-3519 Loading...
- mentioned in
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...