Skip to content

Validate stored parameters in TomEEPbkdf2PasswordHash - #3073

Open
rzo1 wants to merge 1 commit into
mainfrom
pbkdf2-validate-stored-parameters
Open

rzo1 wants to merge 1 commit into
mainfrom
pbkdf2-validate-stored-parameters

Conversation

@rzo1

@rzo1 rzo1 commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

verify() took the algorithm and iteration count from the stored hash without checks, so a weak or tampered hash (e.g. 1 iteration) was accepted. Stored hashes now need a supported PBKDF2 algorithm and at least 1024 iterations, and malformed hashes return false instead of throwing. Setting tomee.security.pbkdf2.allow-weak-parameters=true restores the old behaviour with a warning, which should go into the release notes. Covered by TomEEPbkdf2PasswordHashTest.

Only accept supported PBKDF2 algorithms and at least 1024 iterations; malformed hashes fail verification.
Set tomee.security.pbkdf2.allow-weak-parameters=true to accept legacy hashes.
@rzo1 rzo1 self-assigned this Oct 7, 2026
@rzo1
rzo1 requested a review from jungm October 7, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant