Cipher User Persister
Encrypts and decrypts selected fields of user data. Uses an underlying other user persister plugin to load and store data, i.e. it is applicable to any other user persister plugin.
The method changeUsername(String oldUsername, String newUsername) is not implemented and will throw a NotImplementedException.
Note that data that is not (yet) encrypted can be read as plaintext. The first time the field is written (because of a change in the very field itself), it will be encrypted. This makes migration of data and mixture with encrypted and non-encrypted data possible. It also implies that this encryption provides secrecy (confidentiality) but no authenticity!
The following restrictions apply when using data field encryption:
- Encryption can only be applied to context data fields.
- Encryption can only be applied to string type fields.
- Encryption cannot be applied to the username (even if part of the context data container)
- Searching on encrypted fields is not supported.
- If encrypting a context data property that is also used by other persister plugins (e.g. a credential persister plugin), make sure that the other plugin also encrypts the field.
- Note that encrypted strings are larger than their plain counterpart. Make sure to allow long strings in the underlying persister plugin. The shortest encrypted string is 38 characters long. For longer strings, doubling the plain string length makes a good upper boundary but some encryption mechanisms will still produce much longer output.
userPersister) encryptedContextProperties) Specifies a list of names of string context data properties that have to be stored encrypted on the database.
cipherPassword) Password used for the encryption and decryption.
If other persister plugins (e.g. a CredentialPersister plugin) also use encryption on context data fields listed in this plugin, make sure they use the same password.
This property supports the extended string syntax, i.e. its value may be configured scrambled or in an external file (see example values).
type: CipherUserPersister
id: CipherUserPersister-xxxxxx
displayName:
comment:
properties:
cipherPassword:
encryptedContextProperties:
userPersister: