Difference between revisions of "NF12 Improve Password Hashing"
From iDempiere en
(Created page with "= '''Feature:''' Improve Password Hashing= '''Goal:''' Technical '''Developer:''' Carlos Ruiz Heng Sin '''Description:''' Currently pa...") |
CarlosRuiz (talk | contribs) m (recategorize) |
||
| Line 1: | Line 1: | ||
= '''Feature:''' Improve Password Hashing= | = '''Feature:''' Improve Password Hashing= | ||
| − | '''Goal:''' | + | '''Goal:''' Security |
'''Developer:''' [[User:CarlosRuiz|Carlos Ruiz]] [[User:Hengsin|Heng Sin]] | '''Developer:''' [[User:CarlosRuiz|Carlos Ruiz]] [[User:Hengsin|Heng Sin]] | ||
| Line 31: | Line 31: | ||
'''Technical Info:''' [https://idempiere.atlassian.net/browse/IDEMPIERE-6712 IDEMPIERE-6712] | '''Technical Info:''' [https://idempiere.atlassian.net/browse/IDEMPIERE-6712 IDEMPIERE-6712] | ||
| − | [[Category:New Features| | + | [[Category:New Features|S]] |
| − | [[Category:New Features w12| | + | [[Category:New Features w12|S]] |
| − | [[Category:New Features | + | [[Category:New Features Security]] |
Latest revision as of 13:01, 4 November 2025
Feature: Improve Password Hashing
Goal: Security
Developer: Carlos Ruiz Heng Sin
Description:
Currently password hashing is using SHA-512 and salt is generated using SHA1PRNG random generator and 64 bytes.
This ticket make the following changes to improve the security of password hashing in iDempiere:
- Generate salt using the DRBG algorithm and 256 bit strength.
- Add support for PBKDF2 and Argon2 hashing algorithm.
Changes:
1. Added USER_PASSWORD_HASH_ALGORITHM System Configurator entry. Supported values are SHA-512, PBKDF2 and Argon2.
2. Added Password Hash Algorithm parameter to the Convert passwords to hashes process.
Migration of existing SHA-512 hashes:
- Change USER_PASSWORD_HASH_ALGORITHM System Configurator entry to PBKDF2 or Argon2, reset cache.
- User's password will be rehashed using the newly set algorithm when they login next time.
Technical Info: IDEMPIERE-6712
