Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Change Seed or key for OpenDeploy password Encryption?
DavidHugenberg
Hello
Wondering if any one has had success in changing their seed or key for OpenDeploy encrypted passwords?
I currently believe the key is not very strong, and actually very wea,k as if you have the encrypted password and know where it came from, you can decrypt it. If you have changed it, what rules did you use to create a strong key?
Thanks
Dave
Find more posts tagged with
Comments
Rick Poulin
You can change it (and I have clients that successfully have), but I've honestly never seen the point. Anybody that has access to see your property/config files where you've ENC()oded strings also has the ability to read the key file. The only way to increase security is to have the key come from somewhere other than the local machine, and I'm not sure that's supported by A/I (you CAN do it though..), at which point changing the key makes sense.
DavidHugenberg
Hi
Thanks for the reply.
I'm a bit concerned because I'm not supposed to be able to guess the key, while I need to be able to see the database xml config file. So, to me it's an issue if I know how to decode it. Some one else can guess the key file. So it's just another step of security. As our database xml files, we also keep a copy in an Operations Branch, so more people can see it.
I think I might use some kind of random number generator to replace the contents of the key.
Thanks
Dave
Rick Poulin
Well what I was suggesting is that under normal circumstances, you don't need to guess the key. Having access to read the databases.xml on the file system means you also have access to read the key file, no guessing involved. Now if you're distributing the databases.xml to elsewhere, I can see why you'd want a stronger key.
Look for files called 'passphrase' or 'key' without any extension (it's the same idea, they just called it differently in different parts of the app). To change the OD one, you can change the passphrase and then reencode your encrypted values with the utility in ODNG\bin. This does cascade into TeamSite, where you'll also have to update passphrases/keys and possibly regenerate some more encrypted property values. There's for sure one that needs to be updated in CSF (if you have the OD admin GUI installed) and another in TeamSite\private\etc. The changes may cascade to the webapps, I don't recall.