Why does the JDBC provider store passwords in the clear

dsrand's picture
Generally this is considered a bad idea since anyone who (illicitly) gains access to the database will know all the passwords. Normally the password is run through a crytographic hash with a salt value to guard against rainbow dictionary attacks.
dimuthul's picture

Hi, This is fixed in the

Hi, This is fixed in the trunk. We use salted hashed passwords in the trunk. Thank you, DimuthuL
library project main code
Learn Cloud
Learn
Cloud

The WSO2 Application Server is a reliable application server that can host your enterprise web applications. The WSO2 Application Server as a Service is offered in StratosLive, the WSO2 Platform as a Service. This article explains how a simple web application can be developed and deployed from Carbon Studio to the WSO2 Application Server...

Latest Webinar
Different groups within an organization need to monitor different Key Performance Indicators (KPIs) - An operations team will be interested in the response times of business services and loads of each service,..
Thursday, February 9th 2012, 09.00 AM (PST)

Thursday, February 9th 2012, 10.00 AM (GMT)