Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-3104

Use a random salt for SSHA password encoding

    XMLWordPrintable

Details

    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

    Description

      LdapSshaPasswordEncoder uses a site-wide salt value. This is enough to prevent cracking passwords with hashes from another instance, but random salt would improve resistance to a site-wide attempt at password cracking, as well as hiding cases of password collision between users.

      Attachments

        Issue Links

          Activity

            People

              jwalton joe
              jwalton joe
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: