cloudstack-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Venkata Siva Vijayendra Bhamidipati" <>
Subject Re: Review Request: Make SHA256Salt the default password encoding and authentication mechanism for cloudstack
Date Wed, 03 Apr 2013 00:31:28 GMT

This is an automatically generated e-mail. To reply, visit:

(Updated April 3, 2013, 12:31 a.m.)

Review request for cloudstack, Hugo Trippaers, Kelven Yang, and Min Chen.


Uploading new diff since older patch won't apply due to changes checked into master as part
of b798c451141c32d46322aae83063eeaa9634b337.


Changing default password encoding mechanism from MD5 to SHA256Salted.

This addresses bug CS-1734.

Diffs (updated)

  api/src/org/apache/cloudstack/api/command/admin/account/ 89673ea 
  api/src/org/apache/cloudstack/api/command/admin/user/ fb29e1a 
  api/src/org/apache/cloudstack/api/command/admin/user/ 1f31662 
  client/tomcatconf/ 636eac2 
  client/tomcatconf/ 0ddb428 
  client/tomcatconf/ 0b02eb6 
  developer/developer-prefill.sql 6300d35 
  plugins/user-authenticators/ldap/src/com/cloud/server/auth/ 61eebe5

  plugins/user-authenticators/md5/src/com/cloud/server/auth/ 026125e

  server/src/com/cloud/server/ d0904e1 
  server/src/com/cloud/user/ 40db4ed 



Manual testing done for both oss and nonoss components. Both admin and users added later are
encoded according to the scheme configured, and authenticated by the same scheme.

To change the order of the schemes, modify the following list properties in client/tomcatconf/
or client/tomcatconf/ as applicable, to the desired order:

    <property name="UserAuthenticators">
            <ref bean="SHA256SaltedUserAuthenticator"/>
            <ref bean="MD5UserAuthenticator"/>
            <ref bean="LDAPUserAuthenticator"/>
            <ref bean="PlainTextUserAuthenticator"/>

    <property name="UserPasswordEncoders">
            <ref bean="SHA256SaltedUserAuthenticator"/>
             <ref bean="MD5UserAuthenticator"/>
             <ref bean="LDAPUserAuthenticator"/>
            <ref bean="PlainTextUserAuthenticator"/>


Venkata Siva Vijayendra Bhamidipati

  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message