Uploaded image for project: 'Directory ApacheDS'
  1. Directory ApacheDS
  2. DIRSERVER-261

Storing user passwords other than in clear

    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Closed
    • Blocker
    • Resolution: Fixed
    • pre-1.0
    • 1.0-RC1
    • None
    • None

    Description

      Because the admin user is allowed to see everything, I suggest to store the attribute values for user password other than in clear. I nice solution would be to make this configurable (other server products allow comparable functionality):

      • Configure a hash function to use for password storage (e.g. MD5, SSHA, ...)
      • Allow clients to store the value as a hashed value on their own as well (calculated with a function other than the configured one, if they like)
      • Enable simple bind with value in clear text (hash value calculated within the server and compared against the stored value)
      • Still allow clear passwords, because some authentication mechanisms need this (e.g. DIGEST-MD5)

      Hashed values does not add that much security, but at least is is harder for admin to catch a password and commit it to his/her memory.
      Some products even allow to encrypt the password (two-way), but I think the features above should do for the first run.

      Attachments

        Issue Links

          Activity

            People

              szoerner Stefan Zoerner
              szoerner Stefan Zoerner
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: