This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM 9 Password Storage

Hi there,

 

while using the API, I figured out that passwords for internal users are stored as md4-hashes.

According to Wikipedia: "As of 2007, an attack can generate collisions in less than 2 MD4 hash operations" [1]. That was 10 years ago...

 

Is there any possibility to change the hash algorithm to something useful / secure?

I know that I can use alternative authentication backends, but that's explicitly not what I want.

 

Thanks in advance.

Best,

Alk

 

[1] en.wikipedia.org/.../MD4



This thread was automatically locked due to age.
  • Hey Bob,

    are passwords from the backends are also cached this way or only local accounts?

    Two years ago I found the issue with the unencrypted backend passwords in the logfiles when being in debug mode (see older posts in this thread). This has been fixed. Ist this another way for administrators to decrypt passwords of remote users?

    Best regards,
    Bernd