Bug #23208
open
Add a warning in the logs when using local auth with non-bcrypt passwords
Added by Alexis Mousset over 1 year ago.
Updated 15 days ago.
Status:
Pending technical review
Description
The old hashes should be replaced fro security. A rudder-users.xml
access without it would very likely lead to password recovery using rainbow tables.
- Status changed from New to In progress
- Assignee set to Alexis Mousset
- Status changed from In progress to Pending technical review
- Assignee changed from Alexis Mousset to François ARMAND
- Pull Request set to https://github.com/Normation/rudder/pull/4944
- Target version changed from 8.0.0~beta1 to 8.0.0~beta2
- Target version changed from 8.0.0~beta2 to 8.0.0~beta3
- Target version changed from 8.0.0~beta3 to 8.1.0~alpha1
- Target version changed from 8.1.0~alpha1 to 8.1.0~beta1
- Target version changed from 8.1.0~beta1 to 8.1.0~beta2
- Target version changed from 8.1.0~beta2 to 8.1.0~rc1
- Target version changed from 8.1.0~rc1 to 8.1.0
- Target version changed from 8.1.0 to 8.1.1
- Target version changed from 8.1.1 to 8.1.2
- Target version changed from 8.1.2 to 8.1.3
- Target version changed from 8.1.3 to 8.1.4
- Target version changed from 8.1.4 to 8.1.5
- Target version changed from 8.1.5 to 8.1.6
- Target version changed from 8.1.6 to 8.1.7
- Target version changed from 8.1.7 to 8.1.8
- Target version changed from 8.1.8 to 8.1.9
Also available in: Atom
PDF