[
https://issues.jboss.org/browse/WFLY-11013?page=com.atlassian.jira.plugin...
]
Martin Choma commented on WFLY-11013:
-------------------------------------
{code}echo -n "admin" | openssl dgst -md5 -binary | openssl base64{code}
would be not enough. I really expect in DB
<algorithm>:<iterations>:<base64(salt)>:<base64(hash)>, it means
something like
PBKDF2WithHmacSHA256:64:ISMvKXpXpadD...:ISMvKXpXpadD...
I would expect that is what would be returned by
{{pbkdf2PasswordHash.generate("HelloWorld".toCharArray())}}
Hash encoding Exception when using @DatabaseIdentityStoreDefinition
-------------------------------------------------------------------
Key: WFLY-11013
URL:
https://issues.jboss.org/browse/WFLY-11013
Project: WildFly
Issue Type: Bug
Components: Security
Affects Versions: 14.0.0.Final
Environment: WildFly 14. Generic Linux. JDK 8/9
Reporter: Francesco Marchioni
Assignee: Darran Lofthouse
Attachments: javaee8-secure-servlet.zip
When deploying one application using @DatabaseIdentityStoreDefinition, upon successful
login, the following exception is thrown
{code:java}
java.lang.IllegalArgumentException: Bad hash encoding
at
org.glassfish.soteria.identitystores.hash.Pbkdf2PasswordHashImpl$EncodedPasswordHash.decode(Pbkdf2PasswordHashImpl.java:209)
at
org.glassfish.soteria.identitystores.hash.Pbkdf2PasswordHashImpl$EncodedPasswordHash.<init>(Pbkdf2PasswordHashImpl.java:191)
at
org.glassfish.soteria.identitystores.hash.Pbkdf2PasswordHashImpl.verify(Pbkdf2PasswordHashImpl.java:147)
at
org.glassfish.soteria.identitystores.DatabaseIdentityStore.validate(DatabaseIdentityStore.java:121)
at
org.glassfish.soteria.identitystores.DatabaseIdentityStore.validate(DatabaseIdentityStore.java:101)
at
org.jboss.weldx.security.enterprise.identitystore.IdentityStore$635317201$Proxy$_$$_WeldClientProxy.validate(Unknown
Source)
at
org.glassfish.soteria.cdi.DefaultIdentityStoreHandler.validate(DefaultIdentityStoreHandler.java:97)
{code}
--
This message was sent by Atlassian JIRA
(v7.5.0#75005)