Hello all,

I'm working on integrating OFBiz with an external system that uses bcrypt for 
password hashing ($2a$ format). 

Since OFBiz is not our source of truth for user credentials, I'd like to:

1. Store bcrypt hashes directly in user_login.current_password
2. Extend OFBiz's authentication to verify bcrypt hashes alongside PBKDF2/SHA256

I've implemented a custom authenticator using org.mindrot:jbcrypt that:
- Checks bcrypt hashes first (for external users)
- Falls back to HashCrypt for internal users

Would the community be interested in:
- A patch to add native bcrypt support to HashCrypt?
- Documentation on extending authentication for external password schemes?
- A new JIRA issue to track this feature?

Current OFBiz supports:
- SHA-1 (legacy)
- MD5 (legacy)
- PBKDF2 (SHA256, SHA384, SHA512) [OFBIZ-8537]

Adding bcrypt would align OFBiz with modern security best practices and improve 
interoperability with systems like WordPress, Django, etc.

Any thoughts?

Warm regards


Carsten

Reply via email to