Issue 2551252

Modify default rounds for password_pbkdf2_default_rounds to match OSWAP
Type: security Severity: normal
Components: Web interface Versions:
Status: new
rouilj
Priority: : Blocker, Effort-Low, StarterTicket

Created on 2022-12-23 03:46 by rouilj, last changed 2022-12-23 03:46 by rouilj.

msg7699 Author: [hidden] (rouilj) Date: 2022-12-23 03:46
We use sha1 along with PBKDF2.

recommends 720,000 iterations not 10000.

Change config default to 720,000.

Changing the default will not invalidate existing passwords hashes. They will still
be usable.

Existing passwords will still retain the 10000 iteration number.
Also because of issue 2551251, passwords will not be automatically re-encrypted when user
logs in via web interface.
