I've seen in the IWA_User table that password are encrypted. Is it possible to know which enprytion is used ? Is it possible to configure another ?

Before 6.2: The password is encrypted using a non standard alghorithm. It is not possible to change the alghorithm used for encrypting passwords at the moment.

After 6.2: We use state of the art standard algorithms to encrypt passwords. For user passwords bcrypt is used to hash the password. For passwords used in external database, web services etc. we use AES.


Hi Reto

Is there any strategy to migrate existing users with old passwords from pre-6.2 to 6.2?

(24.06.2016 at 04:30) Genzer Hawker

Hi Yes there is, the passwords will be automatically migrated the first time you start 6.2.

(24.06.2016 at 08:16) Reto Weiss ♦♦

