← Back to plugin index

History Password Hash

Description
This plugin adds password history functionality to any password hash plugin.

It encodes password history information in a list of password hashes.
The plugin can be configured to base64-encode the resulting hash value.

Note that this plugin does also implement the extension point PasswordHash, i.e. it can be used to verify passwords. Further, the plugin can operate on both plain hash values without history and on hash values produced by itself containing history information. Thus, the plugin can be used when introducing the password history on existing data (without password history) without having to migrate the data.
The code verifying passwords must not know of the new concept "password history". The changing a password (or setting one), however, must use the corresponding methods of extension point "PasswordHashWithHistory".

Type name
PasswordHistoryHash
Class
com.airlock.iam.core.misc.util.password.hash.PasswordHistoryHash
May be used by
Properties
Password Hash (passwordHash)
Description
The plugin hash function used for password verification and hashing.

Since the hash value of the configured password hash plugin is considered binary data in any case and base64-encoding is added later (optional, see other configuration property), it does not make much sense to use a password hash function that returns a base64-encoded hash value. It will work but it will make the resulting hash value longer.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Encode Base64 (encodeBase64)
Description
If this property is set to TRUE, the resulting password hash value is base64-encoded and can be treated as string. This is the default.
Attributes
Boolean
Optional
Default value
true
Max History Length (maxHistoryLength)
Description

Defines the maximum number of passwords stored in the history for a single user.

A value of 5, for example, means that the five most recently set passwords are stored, excluding the currently hashed password.

Note that the maximum size of the password history is also limited by the capacity of the "pwd_hash" column in the table "medusa_user". To ensure that users do not run into errors when trying to change their password, you should set the history length low enough to avoid exceeding the character limit of the "pwd_hash" database column. By default, this is a limit of 4000 characters.

Some password hash algorithms (for example, encrypted hashes) produce much longer entries for the password history than others.

Attributes
Integer
Optional
Default value
5
Case Insensitive Storage (caseInsensitiveStorage)
Description
If this property is set to TRUE, the password is matched case insensitively. Notice though that if this property is enabled after some passwords were already hashed, the following property "Also Try Upper Case" has to be enabled as well. Notice that this only affects newly stored passwords (for example after a password change).
This feature is implemented by simply converting the passwords to uppercase before hashing them.
Attributes
Boolean
Optional
Default value
false
Also Try Upper Case (alsoTryUpperCase)
Description
This property is only relevant when matching passwords case-insensitively or if they were stored so previously.
If enabled, user-supplied passwords will not only be checked exactly as entered but also in uppercase to allow case-insensitive matching.
Leave this setting enabled when disabling case insensitive storage later on to still recognize the previously stored passwords.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: PasswordHistoryHash
id: PasswordHistoryHash-xxxxxx
displayName: 
comment: 
properties:
  alsoTryUpperCase: false
  caseInsensitiveStorage: false
  encodeBase64: true
  maxHistoryLength: 5
  passwordHash: