Active InfoActive Info  Display List of Info MembersMemberlist  Search The InfoSearch  HelpHelp
  RegisterRegister  LoginLogin
ASPProtect Version 8.x Support
 CJWSoft Support Info : ASPProtect Version 8.x Support
Subject Info: Use different PW encryption scheme A d d  -  P o s tAdd P o s t
Author
Message << Prev Info | Next Info >>
afifm
New User
New User


Joined: August/27/2004
Location: United States
Online Status: Offline
Info: 15
Added: February/28/2009 at 10:11am | IP Logged Quote afifm

I have a legacy database which will fit nicely with this product except for the password encryption scheme. I would like to keep my current encryption scheme (SHA256). Could you point to me where in this application I need to invoke the SHA256 function to replace the encryption scheme which comes with product?

__________________
Best regards,

Mo
Back to Top View afifm's Profile Search for other info by afifm
 
cwilliams
Admin Group
Admin Group
Avatar
CJWSoft Web Software Developer

Joined: April/06/2004
Online Status: Offline
Info: 1769
Added: February/28/2009 at 10:25am | IP Logged Quote cwilliams

The function is in the "config_inc.asp" file in the root...

Be aware that I am not exactly sure that changes to that function will be enough. You might have to track down any time it is envoked and make small changes as well, or maybe not, all depends..

Also, I believe SHA is a hash, not encryption (meaning it's one way and not reversible) so your gonna have issues with that too. One that comes to mind is the forgotten password feature. You'll have to rework it because you won't be able to decrypt the password and send it to the person. You'll have to do a... send email click on link... go to system.. change password.. type of scenario.

And then there is SALT.. if your hashed passwords had SALT then you have to incorporate all of that that. That could be tricky.

Another thing that would have issues is the expired password feature which store records of a users previous passwords in an encrpted array..  so someone has to choose a password that hasn't been chosen.. that could all break.

Keep in mind too that the free .NET authentication add-on you won't be able to change the encryption/decryption as we don't give out the source code..

I do not support things like this but what I have told you should help.

__________________

Best Regards, Christopher Williams www.CJWSoft.com
Back to Top View cwilliams's Profile Search for other info by cwilliams Visit cwilliams's Homepage
 

If you wish to make a comment to this info you must first login
If you are not already registered you must first register

  A d d  -  P o s tAdd P o s t
Printable version Printable version

Info Jump
You cannot add new info in this area
You cannot add to info in this area
You cannot delete your info in this area
You cannot edit your info in this area
You cannot create polls in this area
You cannot vote in polls in this area


Active Server Pages asp search engine active server page asp application components tutorial CJWSoft ASPProtect ASPBanner ASPClassifieds www.aspprotect.com, www.powerasp.com,www.aspclassifieds.com,www.aspphotogallery.com,www.codewanker.com