Skip to content

Verify Tomcat user identity store passwords with the realm CredentialHandler - #3074

Open
rzo1 wants to merge 1 commit into
mainfrom
tomcat-user-identitystore-credential-handler
Open

rzo1 wants to merge 1 commit into
mainfrom
tomcat-user-identitystore-credential-handler

Conversation

@rzo1

@rzo1 rzo1 commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

TomEEDefaultIdentityStore compared the stored tomcat-users.xml password with plain equals, so digested passwords never matched their cleartext while the digest itself authenticated. It now verifies through the CredentialHandler of the UserDatabaseRealm bound to the same resource, falls back to a constant-time plaintext comparison with a warning if no such realm exists, and returns INVALID_RESULT for a wrong password. Adds unit tests and a new arquillian-tomee-security-tests module covering digested, plaintext and realm-less setups.

Digested passwords in tomcat-users.xml now verify against the cleartext;
the stored digest is rejected and wrong passwords return INVALID.
@rzo1 rzo1 self-assigned this Oct 7, 2026
@rzo1
rzo1 requested a review from jungm October 7, 2026 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant