[keycloak-user] Is LDAP Bind Credential encrypted in the database?

Bruno Oliveira bruno at abstractj.org
Fri Dec 9 05:22:50 EST 2016


Hi Michael,

On 2016-12-09, Michael Furman wrote:
> Hi all,
> Is LDAP Bind Credential encrypted in the database?
> What algorithm is used?

Take a look at https://keycloak.gitbooks.io/server-adminstration-guide/content/topics/threat/password-db-compromised.html

> How can I encrypt the configuration of the custom authenticator (https://keycloak.gitbooks.io/server-developer-guide/content/v/2.4/topics/auth-spi.html)?

It might be possible by implementing a custom authenticator SPI. TBH I
never tried. Although, I don't see the real motivation behind it.

>  Best regards,
>     Michael
>
> _______________________________________________
> keycloak-user mailing list
> keycloak-user at lists.jboss.org
> https://lists.jboss.org/mailman/listinfo/keycloak-user

--

abstractj
PGP: 0x84DC9914


More information about the keycloak-user mailing list