← Back to plugin index

Encrypted Password Hash

Description

Stores the password hash in encrypted form. It will first call the internal hash function and then encrypt the resulting hash.

If a password history is required, wrap this plugin in a 'History Password Hash'. However, bear in mind that an encrypted hash can be longer than the hash value itself. This affects the number of possible entries of 'Max History Length' in 'History Password Hash'.

Type name
EncryptedPasswordHash
Class
com.airlock.iam.core.misc.util.password.hash.EncryptedPasswordHashConfig
May be used by
Properties
Keystore (keystore)
Description
The configuration of the keystore. The keystore is used to load the secret key for the encryption and decryption of the hash.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Encryption Key Alias (encryptionKeyAlias)
Description
The alias of the secret symmetric key in the given keystore to encrypt the hash.
Attributes
String
Mandatory
Example
mykey
Encryption Key Password (encryptionKeyPassword)
Description
The password of the secret key to encrypt the hash.
Attributes
String
Mandatory
Sensitive
Cipher Transformation (cipherTransformation)
Description
The cipher to encrypt the hash. A symmetric cipher is required. The supported symmetric ciphers are:
  • AES/GCM/NoPadding
  • AES/CBC/PKCS5Padding
  • AES/ECB/PKCS5Padding (not recommended)
Caution: Changing the cipher in productive setups means that existing hashes cannot be decrypted anymore. When changing the encryption cipher, make sure to configure the previous cipher in the Legacy Hash Functions.
Attributes
String
Optional
Default value
AES/GCM/NoPadding
Suggested values
AES/GCM/NoPadding, AES/CBC/PKCS5Padding, AES/ECB/PKCS5Padding
YAML Template (with default values)

type: EncryptedPasswordHash
id: EncryptedPasswordHash-xxxxxx
displayName: 
comment: 
properties:
  cipherTransformation: AES/GCM/NoPadding
  encryptionKeyAlias:
  encryptionKeyPassword:
  hashFunction:
  keystore: