No description
Find a file
Thomas Darimont e7363905fa Change password hashing defaults according to OWASP recommendations (#16629)
Changes according to the latest [OWASP cheat sheet for secure Password Storage](https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2):

- Changed default password hashing algorithm from pbkdf2-sha256 to pbkdf2-sha512
- Increased number of hash iterations for pbkdf2-sha1 from 20.000 to 1.300.000
- Increased number of hash iterations for pbkdf2-sha256 from 27.500 to 600.000
- Increased number of hash iterations for pbkdf2-sha512 from 30.000 to 210.000
- Adapt PasswordHashingTest to new defaults
- The test testBenchmarkPasswordHashingConfigurations can be used to compare the different hashing configurations.
- Document changes in changes document with note on performance and how
  to keep the old behaviour.
- Log a warning at the first time when Pbkdf2PasswordHashProviderFactory is used directly

Fixes #16629

Signed-off-by: Thomas Darimont <thomas.darimont@googlemail.com>
2024-01-24 18:35:51 +01:00
.github Exclude ubuntu-latest (sanity-check-zip) as it is running the full zip (#26463) 2024-01-24 16:48:41 +00:00
.idea Add Intellij project icon 2023-09-18 12:39:16 +02:00
.mvn Allow incremental build for the themes (#25405) 2023-12-11 08:35:28 +01:00
adapters Supporting EdDSA 2024-01-24 12:10:41 +01:00
authz Add a toggle to use context attributes on the regex policy provider 2024-01-10 16:15:25 -03:00
boms Upgrade nexus staging maven plugin version (#21428) 2023-07-04 11:00:04 +00:00
common Added Client Type feature flag to begin client type work (#26389) 2024-01-24 12:07:07 +00:00
core Supporting EdDSA 2024-01-24 12:10:41 +01:00
crypto Fix various bugs and issues in crypto/elytron (#23102) 2023-10-03 09:42:57 +02:00
dependencies Delete map dependencies from dependency management 2023-11-08 13:53:17 +01:00
distribution Remove Jetty 9.4 adapters (#26261) 2024-01-24 11:17:29 +01:00
docs Change password hashing defaults according to OWASP recommendations (#16629) 2024-01-24 18:35:51 +01:00
examples Fix rest provider example for kc >= 23 2024-01-10 18:26:53 -03:00
federation Map Store Removal: Rename Legacy* classes (#26273) 2024-01-23 13:50:31 +00:00
integration Use email verification instead of executing action for send-verify-email endpoint 2024-01-11 16:28:02 -03:00
js fix: hardcoded conditional rendering of client secret input field (#25776) 2024-01-24 16:30:22 +01:00
misc Showing the original exception plus any swallowed exceptions. (#25428) 2023-12-13 11:56:08 +01:00
model Map Store Removal: Rename Legacy* classes (#26273) 2024-01-23 13:50:31 +00:00
operator Fix createdAt format in Operator CSV (#26428) 2024-01-24 16:41:44 +01:00
quarkus Stabilizing the FipsDistTest 2024-01-24 16:54:56 +01:00
rest Enable user profile by default 2024-01-11 12:48:44 -03:00
saml-core Escape action in the form_post response mode (#60) 2023-12-18 18:10:41 -03:00
saml-core-api Adds com.sun.xml.ws.rt dependency to saml-core-api 2023-04-27 13:36:54 +02:00
server-spi Change password hashing defaults according to OWASP recommendations (#16629) 2024-01-24 18:35:51 +01:00
server-spi-private Change password hashing defaults according to OWASP recommendations (#16629) 2024-01-24 18:35:51 +01:00
services fix: hardcoded conditional rendering of client secret input field (#25776) 2024-01-24 16:30:22 +01:00
testsuite Change password hashing defaults according to OWASP recommendations (#16629) 2024-01-24 18:35:51 +01:00
themes Enable PKCE by default for Keycloak JS (#26412) 2024-01-23 14:04:13 +01:00
util Artifact SLF4J LOG4J-12 has been relocated (#20113) 2023-05-05 13:57:45 +02:00
.gitattributes Use lf as line-ending for sh files 2022-07-19 08:57:57 +02:00
.gitignore gitignore update 2023-12-18 19:18:18 -03:00
.gitleaks.toml Removing testsuite/performance from main Keycloak repository (#15950) 2022-12-15 14:43:24 +01:00
ADOPTERS.md Update ADOPTERS.md (#23049) 2023-09-07 12:59:55 +00:00
CONTRIBUTING.md Add DCO to CONTRIBUTING.md (#24384) 2023-10-31 08:44:43 +01:00
get-version.sh
GOVERNANCE.md Removed links from relocated repositories (#19703) 2023-04-13 12:59:43 -04:00
LICENSE.txt
MAINTAINERS.md Add Alexander Schwartz to the list of maintainers 2023-06-27 06:45:06 -03:00
maven-settings.xml [KEYCLOAK-11764] Upgrade to Wildfly 19 2020-04-24 08:19:43 -03:00
mvnw Update Maven Wrapper to 3.2.0 2023-09-12 08:56:15 +02:00
mvnw.cmd Update Maven Wrapper to 3.2.0 2023-09-12 08:56:15 +02:00
pom.xml Supporting EdDSA 2024-01-24 12:10:41 +01:00
PR-CHECKLIST.md Introduce CODEOWNERS (#16637) 2023-01-30 13:05:45 +01:00
README.md Minor spelling adjustments (#23106) 2023-09-11 06:55:38 +00:00
set-version.sh Fix set-version.sh's handling of NPM versions (#23638) 2023-10-04 08:00:53 +02:00

Keycloak

Keycloak is an Open Source Identity and Access Management solution for modern Applications and Services.

This repository contains the source code for the Keycloak Server, Java adapters and the JavaScript adapter.

Help and Documentation

Reporting Security Vulnerabilities

If you have found a security vulnerability, please look at the instructions on how to properly report it.

Reporting an issue

If you believe you have discovered a defect in Keycloak, please open an issue. Please remember to provide a good summary, description as well as steps to reproduce the issue.

Getting started

To run Keycloak, download the distribution from our website. Unzip and run:

bin/kc.[sh|bat] start-dev

Alternatively, you can use the Docker image by running:

docker run quay.io/keycloak/keycloak start-dev

For more details refer to the Keycloak Documentation.

Building from Source

To build from source, refer to the building and working with the code base guide.

Testing

To run tests, refer to the running tests guide.

Writing Tests

To write tests, refer to the writing tests guide.

Contributing

Before contributing to Keycloak, please read our contributing guidelines.

Other Keycloak Projects

License