← Back to plugin index

Argon2id Password Hash

Description
This is a password hash plugin that uses Argon2id for hashing. Argon2id is a key derivation function that is designed to be computationally expensive and memory-hard. This makes it resistant to brute-force attacks.

The configuration allows you to adjust the parameters of the algorithm (m, t, and p). Correctly tuning these parameters is crucial to ensuring strong security and reasonable performance on the target hardware.

Benchmark tests should be performed with this plugin on the actual hardware of the production system to determine the highest possible parameters while ensuring a good user experience (e.g., acceptable authentication times). See also Performance tuning and scaling best practices in the documentation.

The default configuration settings are based on the latest OWASP security recommendations and do not take specific hardware characteristics into account.

All three parameters (m, t, and p) are stored with the password hash and used to check passwords. Changing the values does not break existing password hashes. The salt length is 16 bytes, and the hash (tag) length is 32 bytes. However, since the hash parameters are stored as well, an Argon2id hash is longer than a Scrypt hash, which may affect the number of hashes in a "History Password Hash" plugin.

The persisted hash is stored as a PHC-formatted string.

Type name
Argon2idPasswordHash
Class
com.airlock.iam.core.misc.util.password.hash.Argon2idPasswordHash
May be used by
Properties
Memory size (KiB) (memorySizeKb)
Description
The amount of memory to use (m), in kibibytes. Minimum allowed is 8*p KiB as required by RFC 9106. This primarily affects memory cost.
Attributes
Integer
Optional
Default value
19456
Iterations (iterations)
Description
Number of passes (t). This primarily affects CPU cost.
Attributes
Integer
Optional
Default value
2
Parallelism (parallelism)
Description
Number of lanes (p). Affects CPU parallelism. Increasing p may reduce single-hash latency on multi-core CPUs but requires a higher minimum memory m (m ≥ 8*p KiB). Values above the number of physical cores usually do not help.
Attributes
Integer
Optional
Default value
1
YAML Template (with default values)

type: Argon2idPasswordHash
id: Argon2idPasswordHash-xxxxxx
displayName: 
comment: 
properties:
  iterations: 2
  memorySizeKb: 19456
  parallelism: 1