Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upGitHub is where the world builds software
Millions of developers and companies build, ship, and maintain their software on GitHub — the largest and most advanced development platform in the world.
Allow other password hashing algorithms #1917
Comments
|
In config.yaml, an option |
To clarify this, we do not sign but hash using crypt-DES. https://security.stackexchange.com/questions/3165/hmac-why-not-hmac-for-password-storage Instead we should target bcrypt, scrypt (sodium) and so on. So the option should be something like scrypt is in Node since 10.5, see https://nodejs.org/api/crypto.html#crypto_crypto_scrypt_password_salt_keylen_options_callback For others we have to check if we can use |
|
Additionally the SHA-3 winner (Keccak) could be an option too (if some need it) available as But we should prefer bcrypt and scrypt. For both we can set the rounds / interations and so the See https://gchq.github.io/CyberChef/?op=Bcrypt and https://gchq.github.io/CyberChef/?op=Scrypt |
|
An example of plugin |
|
What a coincidence I'm working on the same issue on some of my projects. I don't have full knowledge about what you do to fix the issue but I just bump to those articles: This one is for strengthening ldap passwords using linux crypt: https://www.redpill-linpro.com/techblog/2016/08/16/ldap-password-hash.html. I don't even know that crypt would generate passwords in another formats, so on ldap you generate a SHA512, SHA256 or Blowfish and stored it the hash signaled as crypt and ldap will use the lib with that strong algo pointed in the hash. This one is about peper and how to validate the generated hash: https://crackstation.net/hashing-security.htm. In the case of pepper that must be considered well as old passwords are not peppered so you have a compatibility issue that should be solved in your system before. On my projects I can get direct interface to unix cyrpt but I don't know if there is anything available in JavaScript. I hope that could be useful information on this task. |
|
Thanks @piraz really appreciated |
My reason:
Currently, we support verify on multiple formats but we do not on the sign the password, we shoud allow this plugin to sign with something different than
CRYPThttps://httpd.apache.org/docs/2.4/misc/password_encryptions.html
Additional information: