AWS KMS Password Hash
Description
Password hash for AWS Key Management Service (KMS).
The password is first hashed with the defined hash function and then encrypted by AWS KMS.
This plugin does no encoding on the resulting hash. Therefore it should be used in combination with a 'Password Hash Configuration' or 'History Password Hash'.
If a password history is required, wrap this plugin in a 'History Password Hash'. However, bear in mind that an encrypted hash can be longer than the hash value itself. This affects the number of possible entries of 'Max History Length' in 'History Password Hash'.
May be used by
TAN Batch Task Password Hash Configuration History Password Hash Token Data mTAN Handler Adminapp REST API Configuration Persister Password Service Persister Password Service Default Password Repository Default Password Repository Basic Secret Question Settings Administrators Management Token IAK Handler Secret Questions Settings External Database Password Repository External Database Password Repository Credential Secret Generator Persister IAK Verifier Matrix Card Generator Default TAN Service Encrypted Password Hash Combined Password Hash Combined Password Hash Credential Data mTAN Handler Fixed TAN Generator Task OAuth 2.0 Token Generator Settings
Properties
Hash Function (
hashFunction) Description
The password hash function to apply before the hash is encrypted by AWS KMS.
Attributes
Plugin-Link
Mandatory
Assignable plugins
AWS KMS Password Hash Argon2id Password Hash Bcrypt Password Hash Combined Password Hash Encrypted Password Hash History Password Hash Identity Password Hash LDAP Password Hash MD5 Base64 Password Hash MD5 Hex Password Hash Multi Password Hash (LDAP-style) Password Hash Configuration SHA1 Base64 Password Hash SHA1 Hex Password Hash SHA1 Password Hash SHA256 Base64 Password Hash SHA256 Hex Password Hash SHA256 Password Hash Scrypt Password Hash
AWS KMS Settings (
awsKmsSettings) Description
Specifies the AWS account and key material for cryptographic operations.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)
type: AwsKmsPasswordHash
id: AwsKmsPasswordHash-xxxxxx
displayName:
comment:
properties:
awsKmsSettings:
hashFunction: