Details
Description
The BUILTIN authentication scheme protects the passwords by hashing them with the SHA-1 algorithm. It would be nice to have way to specify a different algorithm so that users can take advantage of new, stronger algorithms provided by their JCE provider if so desired.
This issue tracks our response to security vulnerability CVE-2009-4269, which Marcell Major identified. See http://marcellmajor.com/derbyhash.html
Attachments
Attachments
Issue Links
- is related to
-
DERBY-4602 10 failures and 11 errors with IBM weme6.2/j9/cdc-foundation after revision 922304 for DERBY-4483
- Closed
- relates to
-
DERBY-4468 Security weaknesses
- Closed
-
DERBY-4579 Document the configurable hash authentication scheme
- Closed