directory-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Peter Hmelak (JIRA)" <j...@apache.org>
Subject [jira] [Created] (DIRSERVER-1822) Same password can be used multiple times, when SSHA is used for password hash.
Date Wed, 10 Apr 2013 19:31:15 GMT
Peter Hmelak created DIRSERVER-1822:
---------------------------------------

             Summary: Same password can be used multiple times, when SSHA is used for password
hash.
                 Key: DIRSERVER-1822
                 URL: https://issues.apache.org/jira/browse/DIRSERVER-1822
             Project: Directory ApacheDS
          Issue Type: Bug
            Reporter: Peter Hmelak


When using SSHA (salted SHA) for password hashing, no CONSTRAINT_VIOLATION (invalid reuse
of password present in password history) is thrown, if new password is the same as one already
in pwdHistory.

I believe current implementation just compares new password hash, with with ones stored in
pwdHistory.
And because of new salt, no two hashes are ever a-like, even though passwords are the same.

Suggestion for fix:

*Every* salt stored in pwdHistory should be used, together with new password when creating
password hashes, that are then compared with ones already stored in pwdHistory.


--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

Mime
View raw message