Use a random salt for SSHA password encoding

XMLWordPrintable

      LdapSshaPasswordEncoder uses a site-wide salt value. This is enough to prevent cracking passwords with hashes from another instance, but random salt would improve resistance to a site-wide attempt at password cracking, as well as hiding cases of password collision between users.

            Assignee:
            joe
            Reporter:
            joe
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: