You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@syncope.apache.org by "Andrea Patricelli (Jira)" <ji...@apache.org> on 2022/03/02 10:10:00 UTC

[jira] [Created] (SYNCOPE-1666) Security Answer encryption

Andrea Patricelli created SYNCOPE-1666:
------------------------------------------

             Summary: Security Answer encryption 
                 Key: SYNCOPE-1666
                 URL: https://issues.apache.org/jira/browse/SYNCOPE-1666
             Project: Syncope
          Issue Type: Improvement
          Components: core
    Affects Versions: 2.1.10
            Reporter: Andrea Patricelli
             Fix For: 2.1.11, 3.0.0


Security answer is stored as cleartext field, but, since contains sesitive information, must be encrypted. We hav to use the same algorithms available for password.

Provide also an upgrade guide and a migration tool to encrypt passwords on already existing installations.



--
This message was sent by Atlassian Jira
(v8.20.1#820001)