Bcrypt Password Hash
Description
Password hash plugin that uses bcrypt for hashing. Bcrypt only uses the first 72 bytes of the password in UTF-8 encoding. Therefore, consider using a policy to enforce a maximum password length restriction. See https://www.openbsd.org/papers/bcrypt-paper.pdf for more details.
Returns $[version]$[cost]$[22 character salt][31 character hash] as a bcrypt string.
Security note: The bcrypt algorithm is no longer recommended for password hashing. Use "Argon2id Password Hash" instead.
May be used by
TAN Batch Task Password Hash Configuration History Password Hash Token Data mTAN Handler Adminapp REST API Configuration Persister Password Service Persister Password Service Default Password Repository Default Password Repository Basic Secret Question Settings Administrators Management Token IAK Handler Secret Questions Settings External Database Password Repository External Database Password Repository Credential Secret Generator Persister IAK Verifier Matrix Card Generator Default TAN Service Encrypted Password Hash Combined Password Hash Combined Password Hash Credential Data mTAN Handler Fixed TAN Generator Task OAuth 2.0 Token Generator Settings AWS KMS Password Hash
Properties
Cost (Iterations Exponent) (
cost) Description
The exponent used to compute the number of iterations, also known as cost. The actual number of iterations is 2 to the power of the value defined here.
The value must be greater than or equal to 4 and less than or equal to 31. The number of iterations is stored together with the bcrypt string. Therefore, this value can be increased or decreased without losing backward compatibility.
Attributes
Integer
Optional
Default value
12
Version (
version) Description
The version used to generate the password hashes. The implementations of these versions do not differ from one another, therefore you can choose which one is used for generating password hashes.
- $2$: version prefix in the original specification.
- $2a$: version prefix in the revised specification defining encoding and null-terminator explicitly.
- $2y$, $2b$: version prefixes stating explicitly that the implementation is not affected by certain known bugs.
This has no effect when checking passwords as this implementation does not suffer from the known bugs and supports all versions. Therefore, this value can be changed without losing backward compatibility.
Attributes
String
Optional
Default value
2a
Allowed values
2, 2a, 2b, 2y
YAML Template (with default values)
type: BcryptPasswordHash
id: BcryptPasswordHash-xxxxxx
displayName:
comment:
properties:
cost: 12
version: 2a