Bug 1006567 - Only SHA-256 allowed in EAP 6.2 CC evaluated configuration
Summary: Only SHA-256 allowed in EAP 6.2 CC evaluated configuration
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: JBoss Enterprise Application Platform 6
Classification: JBoss
Component: Documentation
Version: 6.2.0
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: GA
: EAP 6.2.2,EAP 6.3.0
Assignee: Tom WELLS
QA Contact: Russell Dickenson
URL:
Whiteboard:
Depends On:
Blocks: 1028353
TreeView+ depends on / blocked
 
Reported: 2013-09-10 20:21 UTC by Ann Marie Rubin
Modified: 2015-05-18 01:29 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-06-02 12:49:18 UTC
Type: Bug


Attachments (Terms of Use)

Description Ann Marie Rubin 2013-09-10 20:21:33 UTC
Document URL: Security Guide

Section Number and Name: 

Describe the issue: 

Suggestions for improvement: 

Additional information: The Security Guide needs to mention that only SHA-256 is allowed in the Common Criteria evaluated configuration.

Comment 1 Russell Dickenson 2013-11-20 00:05:26 UTC
Can you please be more specific about specifically what the "SHA-256" reference applies? I understand just what "SHA-256" is, but I need to know specifics relating to JBoss EAP 6.2.0 so that I can amend the Security Guide appropriately.

Comment 2 Josef Cacek 2014-04-02 12:53:25 UTC
The SHA-256 should be used for password hashing in login modules - UsersRolesLoginModule, DatabaseServerLoginModule.

I.e. users use following module option:
hashAlgorithm=SHA-256

Comment 4 Josef Cacek 2014-04-23 10:22:04 UTC
Verified on docs-stage:
Revision 6.2.2-6
Revision 6.3.0-12


Note You need to log in before you can comment on or make changes to this bug.