Hello all,
I'm working on integrating OFBiz with an external system that uses bcrypt for password hashing ($2a$ format). Since OFBiz is not our source of truth for user credentials, I'd like to: 1. Store bcrypt hashes directly in user_login.current_password 2. Extend OFBiz's authentication to verify bcrypt hashes alongside PBKDF2/SHA256 I've implemented a custom authenticator using org.mindrot:jbcrypt that: - Checks bcrypt hashes first (for external users) - Falls back to HashCrypt for internal users Would the community be interested in: - A patch to add native bcrypt support to HashCrypt? - Documentation on extending authentication for external password schemes? - A new JIRA issue to track this feature? Current OFBiz supports: - SHA-1 (legacy) - MD5 (legacy) - PBKDF2 (SHA256, SHA384, SHA512) [OFBIZ-8537] Adding bcrypt would align OFBiz with modern security best practices and improve interoperability with systems like WordPress, Django, etc. Any thoughts? Warm regards Carsten
