Password Transformers#

Introduction#

A Password Transformer hashes credentials, and verifies credentials against previously hashed ones, using a password hashing algorithm provided by a Password Transformer plugin. It is the way to hash credentials with an algorithm that the Curity Identity Server does not implement itself.

This facility is available since 11.5.

Configuration#

A Password Transformer is configured with a type — one of the algorithms provided by the installed Password Transformer plugins — and that plugin’s settings, such as the cost parameters of the algorithm.

Argon2 and SCrypt hashing are supported through the external hardened-hashing plugin, which provides Password Transformer algorithms for those hashing families.

Usage#

A Password Transformer is used by selecting it as the algorithm of a Credential Manager, which refers to it by its id. Several Credential Managers may use the same Password Transformer, in which case they hash credentials identically and share whatever resources it allocates.

A Credential Transformation Procedure can also obtain a Password Transformer by its id, which lets a procedure hash and verify with a plugin-provided algorithm. Configuring a Password Transformer purely for a procedure to use is a valid setup — it does not have to be referred to by any Credential Manager.

A Password Transformer cannot be deleted while a Credential Manager still refers to it. A procedure names it inside its script text, though, so that reference cannot be checked when the configuration is committed: deleting or renaming a Password Transformer that only a procedure names fails when the procedure runs.

A Credential Manager configured with a Password Transformer is rejected when the server runs in FIPS mode: the server cannot know which cryptographic primitives a plugin uses. Obtaining a Password Transformer from a procedure fails in FIPS mode for the same reason.

Was this helpful?