Feature #50613

Task #49162: Rewrite install tool

Use salted Install Tool password

Added by Nicole Cordes about 7 years ago. Updated almost 3 years ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
Install Tool
Target version:
Start date:
2013-08-01
Due date:
% Done:

100%

PHP Version:
Tags:
Complexity:
Sprint Focus:

Description

To enhanced the security change Install Tool password from md5 hash to salted.


Related issues

Related to TYPO3 Core - Feature #22245: Secure Install Tool Login Closed 2010-03-06
Related to TYPO3 Core - Feature #21423: Install Tool Password gets transmitted plain text Rejected 2009-11-02

Associated revisions

Revision d1199a88 (diff)
Added by Nicole Cordes about 7 years ago

[FEATURE] Use salted Install Tool password

To enhanced the security this patch changes the Install Tool password
from md5 hash to a salted hashed password. Therefore the default
password in the FactoryConfiguration.php is changed. Old md5 hashes get
converted automatically during the boot process of the Install Tool. The
output of the calculated hash is reintroduced when an error occured.
The report modules were adjusted to be able to check salted hashed
passwords.

Resolves: #50613
Releases: 6.2
Change-Id: If02a43780c9c819ebd6da7cbf0acad305f805330
Reviewed-on: https://review.typo3.org/22739
Reviewed-by: Kai Ole Hartwig
Tested-by: Kai Ole Hartwig
Reviewed-by: Christian Kuhn
Tested-by: Christian Kuhn

History

#1 Updated by Gerrit Code Review about 7 years ago

  • Status changed from Accepted to Under Review

Patch set 1 for branch master has been pushed to the review server.
It is available at https://review.typo3.org/22739

#2 Updated by Christian Kuhn about 7 years ago

  • Parent task set to #49162

#3 Updated by Gerrit Code Review about 7 years ago

Patch set 2 for branch master has been pushed to the review server.
It is available at https://review.typo3.org/22739

#4 Updated by Gerrit Code Review about 7 years ago

Patch set 3 for branch master has been pushed to the review server.
It is available at https://review.typo3.org/22739

#5 Updated by Nicole Cordes about 7 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100

#6 Updated by Gerrit Code Review about 7 years ago

  • Status changed from Resolved to Under Review

Patch set 1 for branch master_new has been pushed to the review server.
It is available at https://review.typo3.org/23416

#7 Updated by Nicole Cordes about 7 years ago

  • Status changed from Under Review to Resolved

Already merged.

#8 Updated by Riccardo De Contardi almost 3 years ago

  • Status changed from Resolved to Closed

Also available in: Atom PDF