Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-10855

Add a way to specify in createUser and updateUser commands whether the server should hash the password or the driver already has

    • Type: Icon: Task Task
    • Resolution: Done
    • Priority: Icon: Major - P3 Major - P3
    • 2.5.4
    • Affects Version/s: None
    • Component/s: Security
    • None
    • Minor Change

      For password policy enforcement the server needs to receive the password in plain text.
      For users without SSL, however, they probably want a way to continue the existing behavior of hashing the password in the client before sending it over the wire.

      Need to also figure out what the default should be, what the right interface to control this in the drivers is, etc.

            Assignee:
            spencer@mongodb.com Spencer Brody (Inactive)
            Reporter:
            spencer@mongodb.com Spencer Brody (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: