Scrypt Password Hash
The configuration allows tuning of the algorithm's parameters (N, r, p). Tuning these parameters correctly is crucial to ensure both strong security and reasonable performance on the target hardware.
It is recommended to perform benchmark tests with this plugin on the actual hardware of the productive system to determine the highest possible parameters (security) while still ensuring a good user experience, e.g. acceptable authentication times.
The configuration defaults are based on the latest security recommendations, without taking specific hardware characteristics into account.
Security note: The scrypt algorithm is no longer recommended for password hashing. Use "Argon2id Password Hash" instead.
iterationsExponent) The number of iterations is stored together with the hash value. That means this value can be increased or decreased without losing backward compatibility.
blockSize) The default value should be suitable for most applications. If a higher cost for brute-force attacks is desired, consider adjusting the iteration exponent (N) instead.
This value is not stored with the hash value. Changing it will break compatibility with existing hashes. Use the "Combined Password Hash" to allow for a transition from an old value to a new value.
parallelizationParameter) Must be a positive integer less than or equal to (231-1) / (128 * r * 8), where r is the block size.
The default value should be suitable for most applications. If a higher cost for brute-force attacks is desired, consider adjusting the iteration exponent (N) instead.
This value is not stored with the hash value. Changing it will break compatibility with existing hashes. Use the "Combined Password Hash" to allow for a transition from an old value to a new value.
type: ScryptPasswordHash
id: ScryptPasswordHash-xxxxxx
displayName:
comment:
properties:
blockSize: 8
iterationsExponent: 17
parallelizationParameter: 1