A platform that connects to other systems holds their credentials. How it holds them is a question every security review asks. This release changes the answer on three fronts.
Encryption
- AES-GCM with salt A new authenticated cipher for secrets at rest, with the previous CBC cipher kept under a versioned name for reading what it wrote. A test suite of some 600 lines covers the new one.
- Database-server passwords encrypted Server, SMTP and JMX passwords are stored encrypted; a value loaded from an older configuration is detected as plain and treated accordingly, and the previous value is kept in a backup column populated only once.
Verification and containment
- A verifier that reads the prefix Password verification selects the algorithm from the stored hash's prefix, so nothing in the platform handles a plain password in order to compare it.
- Scripts cannot read a plain password The accessor checks its caller and refuses when invoked from a GraalVM scripting context. The secure wrapper rejects null or blank values and offers verification instead of exposure.
A later release moved user password hashing to Argon2id and rotated JWT keys. This release is about everything else the platform keeps on behalf of other systems.