ofbiz-notifications mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Shi Jinghai (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (OFBIZ-8537) LoginWorker HashCrypt the type of hash for one-way encryption
Date Mon, 05 Dec 2016 10:04:58 GMT

    [ https://issues.apache.org/jira/browse/OFBIZ-8537?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15721830#comment-15721830
] 

Shi Jinghai commented on OFBIZ-8537:
------------------------------------

Thanks Michael for reviewing and Pierre for the suggestion on password format (see https://github.com/hamano/openldap-pbkdf2)!

I'll change flexadmin's password back to SHA as currently the password format of PBKDF2 is
not complied with RFC standard.

> LoginWorker HashCrypt the type of hash for one-way encryption
> -------------------------------------------------------------
>
>                 Key: OFBIZ-8537
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-8537
>             Project: OFBiz
>          Issue Type: New Feature
>          Components: framework
>    Affects Versions: Trunk
>            Reporter: wangjunyuan
>            Assignee: Shi Jinghai
>            Priority: Minor
>              Labels: HashCrypt, PBKDF2, security.properties
>         Attachments: HashCrypt.patch
>
>
> PBKDF2 (Password-Based Key Derivation Function 2) is part of RSA Laboratories' Public-Key
Cryptography Standards (PKCS) series, specifically PKCS #5 v2.0, also published as Internet
Engineering Task Force's RFC 2898. It replaces an earlier key derivation function, PBKDF1,
which could only produce derived keys up to 160 bits long.Add this function to ofbiz ,this
PBKDF2 has four types in Javaļ¼š'PBKDF2WithHmacSHA1','PBKDF2WithHmacSHA256','PBKDF2WithHmacSHA384','PBKDF2WithHmacSHA512'



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Mime
View raw message