Cipher Credential Persister
Encrypts and decrypts selected fields of credential data. Uses an underlying other credential persister plugin to load and store data, i.e. it is applicable to any other credential persister plugin.
Note that data that is not (yet) encrypted can be read as plaintext. The first time the field is written(because of a change in the very field itself), it will be encrypted. This makes migration of data and mixture with encrypted and non-encrypted data possible. It also implies that this encryption provides secrecy (confidentiality) but no authenticity!
The following restrictions apply when using data field encryption:
- Encryption can only be applied to the serial number, the credential data and context data fields.
- Encryption of context data properties can only be applied to string type properties.
- Encryption cannot be applied to the username (even if part of the context data container)
- Searching on encrypted fields is not supported.
- If encrypting a context data property that is also used by other persister plugins (e.g. a user persister plugin), make sure that the other plugin also encrypts the field.
- Note that encrypted strings are larger than their plain counterpart. Make sure to allow long strings in the underlying persister plugin. The shortest encrypted string is 38 characters long. For longer strings, doubling the plain string length makes a good upper boundary.
credentialPersister) encryptSerial) encryptCredentialData) encryptedContextProperties) Specifies a list of names of string context data properties that have to be stored encrypted on the database.
cipherPassword) Password used for the encryption and decryption.
If other persister plugins (e.g. a UserPersister plugin) also use encryption on data fields encrypted in this plugin, make sure they use the same password.
This property supports the extended string syntax, i.e. its value may be configured scrambled or in an external file (see example values).
type: CipherCredentialPersister
id: CipherCredentialPersister-xxxxxx
displayName:
comment:
properties:
cipherPassword:
credentialPersister:
encryptCredentialData: true
encryptSerial: false
encryptedContextProperties: