shiro-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Brian Demers (JIRA)" <>
Subject [jira] [Updated] (SHIRO-445) Mechanism needed to secure passwords in shiro.ini
Date Wed, 25 May 2016 16:04:13 GMT


Brian Demers updated SHIRO-445:
    Fix Version/s:     (was: 1.2.5)

> Mechanism needed to secure passwords in shiro.ini
> -------------------------------------------------
>                 Key: SHIRO-445
>                 URL:
>             Project: Shiro
>          Issue Type: New Feature
>          Components: Authentication (log-in), Specification API
>    Affects Versions: 1.2.2
>         Environment: Any.
>            Reporter: Richard J. Barbalace
>             Fix For: 1.2.6
>         Attachments: mypatch.txt, mypatch2.txt
>   Original Estimate: 24h
>  Remaining Estimate: 24h
> There should be a mechanism to secure passwords stored in shiro.ini for accessing databases
or other data sources, as described in this Shiro user forum post:
> A flexible and extensible approach should allow for passwords to be stored in other INI
or properties files, JNDI resources, databases, key stores, key servers, or other data sources.
 Passwords might be encrypted using a master key, which could likewise be stored in various
data sources.
> I already have an initial patch prepared that allows for passwords to be stored (plaintext
or encrypted with a master key) in other INI files, similar to a shadow password file.  This
can be further extended to use other data sources as needs arise.

This message was sent by Atlassian JIRA

View raw message