Hide Forgot
Document URL: Security Guide Section Number and Name: Describe the issue: Suggestions for improvement: Additional information: The Security Guide needs to mention that only SHA-256 is allowed in the Common Criteria evaluated configuration.
Can you please be more specific about specifically what the "SHA-256" reference applies? I understand just what "SHA-256" is, but I need to know specifics relating to JBoss EAP 6.2.0 so that I can amend the Security Guide appropriately.
The SHA-256 should be used for password hashing in login modules - UsersRolesLoginModule, DatabaseServerLoginModule. I.e. users use following module option: hashAlgorithm=SHA-256
Verified on docs-stage: Revision 6.2.2-6 Revision 6.3.0-12