Encrypted Password Hash
Description
Stores the password hash in encrypted form. It will first call the internal hash function and then encrypt the resulting hash.
If a password history is required, wrap this plugin in a 'History Password Hash'. However, bear in mind that an encrypted hash can be longer than the hash value itself. This affects the number of possible entries of 'Max History Length' in 'History Password Hash'.
May be used by
TAN Batch Task History Password Hash Adminapp REST API Configuration Persister Password Service Persister Password Service Default Password Repository Default Password Repository Basic Secret Question Settings Administrators Management Token IAK Handler Secret Questions Settings External Database Password Repository External Database Password Repository Credential Secret Generator Persister IAK Verifier Matrix Card Generator Default TAN Service Combined Password Hash Combined Password Hash Credential Data mTAN Handler Fixed TAN Generator Task AWS KMS Password Hash
Properties
Hash Function (
hashFunction) Description
The password hash function.
Attributes
Plugin-Link
Mandatory
Assignable plugins
AWS KMS Password Hash Argon2id Password Hash Bcrypt Password Hash Combined Password Hash Encrypted Password Hash History Password Hash Identity Password Hash LDAP Password Hash MD5 Base64 Password Hash MD5 Hex Password Hash Multi Password Hash (LDAP-style) Password Hash Configuration SHA1 Base64 Password Hash SHA1 Hex Password Hash SHA1 Password Hash SHA256 Base64 Password Hash SHA256 Hex Password Hash SHA256 Password Hash Scrypt Password Hash
Keystore (
keystore) Description
The configuration of the keystore. The keystore is used to load the secret key for the encryption and decryption of the hash.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Encryption Key Alias (
encryptionKeyAlias) Description
The alias of the secret symmetric key in the given keystore to encrypt the hash.
Attributes
String
Mandatory
Example
mykey
Encryption Key Password (
encryptionKeyPassword) Description
The password of the secret key to encrypt the hash.
Attributes
String
Mandatory
Sensitive
Cipher Transformation (
cipherTransformation) Description
The cipher to encrypt the hash. A symmetric cipher is required. The supported symmetric ciphers are:
- AES/GCM/NoPadding
- AES/CBC/PKCS5Padding
- AES/ECB/PKCS5Padding (not recommended)
Attributes
String
Optional
Default value
AES/GCM/NoPadding
Suggested values
AES/GCM/NoPadding, AES/CBC/PKCS5Padding, AES/ECB/PKCS5Padding
YAML Template (with default values)
type: EncryptedPasswordHash
id: EncryptedPasswordHash-xxxxxx
displayName:
comment:
properties:
cipherTransformation: AES/GCM/NoPadding
encryptionKeyAlias:
encryptionKeyPassword:
hashFunction:
keystore: