Add a way to specify in createUser and updateUser commands whether the server should hash the password or the driver already has

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Done
    • Priority: Major - P3
    • 2.5.4
    • Affects Version/s: None
    • Component/s: Security
    • None
    • Minor Change
    • None
    • 3
    • None
    • None
    • None
    • None
    • None
    • None

      For password policy enforcement the server needs to receive the password in plain text.
      For users without SSL, however, they probably want a way to continue the existing behavior of hashing the password in the client before sending it over the wire.

      Need to also figure out what the default should be, what the right interface to control this in the drivers is, etc.

            Assignee:
            Spencer Brody (Inactive)
            Reporter:
            Spencer Brody (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: