Uploaded image for project: 'Derby'
  1. Derby
  2. DERBY-528

Support for DRDA Strong User ID and Password Substitute Authentication (USRSSBPWD) scheme

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 10.1.1.0
    • 10.2.1.6
    • None
    • None
    • Normal
    • Security

    Description

      This JIRA will add support for (DRDA) Strong User ID and Password Substitute Authentication (USRSSBPWD) scheme in the network client/server driver layers.

      Current Derby DRDA network client driver supports encrypted userid/password (EUSRIDPWD) via the use of DH key-agreement protocol - however current Open Group DRDA specifications imposes small prime and base generator values (256 bits) that prevents other JCE's to be used as java cryptography providers - typical minimum security requirements is usually of 1024 bits (512-bit absolute minimum) when using DH key-agreement protocol to generate a session key.

      Strong User ID and Password Substitute Authentication (USRSSBPWD) is part of DRDA specifications as another alternative to provide ciphered passwords across the wire.

      Support of USRSSBPWD authentication scheme will enable additional JCE's to be used when encrypted passwords are required across the wire.

      USRSSBPWD authentication scheme will be specified by a Derby network client user via the securityMechanism property on the connection UR - A new property value such as ENCRYPTED_PASSWORD_SECURITY will be defined in order to support this new (DRDA) authentication scheme.

      Attachments

        1. 528_diff_v5.txt
          262 kB
          Francois Orsini
        2. 528_stat_v5.txt
          2 kB
          Francois Orsini
        3. 528_diff_v4.txt
          263 kB
          Francois Orsini
        4. 528_stat_v4.txt
          2 kB
          Francois Orsini
        5. 528_diff_v3.txt
          245 kB
          Francois Orsini
        6. 528_stat_v3.txt
          2 kB
          Francois Orsini
        7. 528_diff_v2.txt
          193 kB
          Francois Orsini
        8. 528_stat_v2.txt
          1 kB
          Francois Orsini
        9. 528_SecMec_Testing_Table.txt
          9 kB
          Francois Orsini
        10. 528_stat_v1.txt
          1 kB
          Francois Orsini
        11. 528_diff_v1.txt
          142 kB
          Francois Orsini

        Activity

          People

            forsini Francois Orsini
            forsini Francois Orsini
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: