Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-2679

Crowd + Apache Directory Server connector submitting changed passwords in plaintext

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: High High
    • 2.4.2
    • 2.3.1, 2.3.2
    • None
    • None
    • Using Crowd and a Apache Directory server

      Setting up Crowd and a Apache directory server, if you try to modify the password from a user and save it, Crowd stores it in Apache as plaintext.

      See the screenshot with a test case.

            [CWD-2679] Crowd + Apache Directory Server connector submitting changed passwords in plaintext

            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 - restricted [ 1509518 ] New: JAC Bug Workflow v3 [ 3365566 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 [ 1391594 ] New: Simplified Crowd Development Workflow v2 - restricted [ 1509518 ]
            Owen made changes -
            Workflow Original: Crowd Development Workflow v2 [ 348297 ] New: Simplified Crowd Development Workflow v2 [ 1391594 ]
            joe made changes -
            Fix Version/s New: 2.4.2 [ 25495 ]
            Fix Version/s Original: 2.4.1 [ 22991 ]
            joe made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Technical Review [ 10028 ] New: Resolved [ 5 ]
            joe made changes -
            Status Original: In Progress [ 3 ] New: Technical Review [ 10028 ]
            joe made changes -
            Status Original: Open [ 1 ] New: In Progress [ 3 ]

            joe added a comment -

            The ApacheDS example sells them short - they also support SSHA, which is better and also our default for OpenLDAP. I'll switch ApacheDS to the same behaviour as OpenLDAP (let encoding be set in the UI, make SSHA the default, use a factory).

            joe added a comment - The ApacheDS example sells them short - they also support SSHA, which is better and also our default for OpenLDAP. I'll switch ApacheDS to the same behaviour as OpenLDAP (let encoding be set in the UI, make SSHA the default, use a factory).

            Justin Koke added a comment - - edited

            We should be using the encryption algorithm specified for the directory, as used by the OpenLDAP implementation.

            Justin Koke added a comment - - edited We should be using the encryption algorithm specified for the directory, as used by the OpenLDAP implementation.
            joe made changes -
            Fix Version/s New: 2.4.1 [ 22991 ]
            Assignee New: joe [ jwalton ]

              jwalton joe
              rgadami Rodrigo Girardi Adami
              Affected customers:
              1 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: