Combination View Flat View Tree View
Threads [ Previous | Next ]
toggle
Vishal Kumar
Password Encryption
January 1, 2013 6:30 AM
Answer

Vishal Kumar

Rank: Junior Member

Posts: 36

Join Date: December 11, 2012

Recent Posts

Is all user passwords is stored encrypted using salted SHA1 in liferay?
Jelmer Kuperus
RE: Password Encryption
January 1, 2013 3:00 PM
Answer

Jelmer Kuperus

Rank: Liferay Legend

Posts: 1190

Join Date: March 10, 2010

Recent Posts

The encryption used is determined by the passwords.encryption.algorithm property
By default it uses unsalted sha iirc, which is not very secure
Vishal Kumar
RE: Password Encryption
January 1, 2013 9:24 PM
Answer

Vishal Kumar

Rank: Junior Member

Posts: 36

Join Date: December 11, 2012

Recent Posts

jelmer kuperus:
The encryption used is determined by the passwords.encryption.algorithm property
By default it uses unsalted sha iirc, which is not very secure

Then in that case, How can i achieve Salted SHA1 algorithm.
Jelmer Kuperus
RE: Password Encryption
January 1, 2013 11:02 PM
Answer

Jelmer Kuperus

Rank: Liferay Legend

Posts: 1190

Join Date: March 10, 2010

Recent Posts

Add

1passwords.encryption.algorithm=SSHA


to your portal-ext.properties

using bcrypt might be even better
Vishal Kumar
RE: Password Encryption
January 2, 2013 12:08 AM
Answer

Vishal Kumar

Rank: Junior Member

Posts: 36

Join Date: December 11, 2012

Recent Posts

jelmer kuperus:
Add

1passwords.encryption.algorithm=SSHA


to your portal-ext.properties

using bcrypt might be even better


Thanks a lot jelmer