Password Hashing Update: MD5 β PBKDF2
Select your preferred language:
Dutch: open the first section
English: open the second section
π³π± Nederlands
TL;DR
passwordstorage.use_pbkdf2=true aanwezig? Dan is het goed.
Key ontbreekt of staat op false? Dan gebruikt de applicatie nog MD5. Voeg de key toe en voer de benodigde testen uit.
Extra aandacht voor CMS-websites, oude NNetwork-websites en applicaties met veel webserviceverkeer.
Waarom deze wijziging?
Conform onze Information Security Best Practices adviseren we om MD5 uit te faseren en gebruik te maken van PBKDF2 voor wachtwoordopslag.
MD5 wordt beschouwd als een verouderde hashingmethode en voldoet niet meer aan actuele beveiligingsrichtlijnen. PBKDF2 biedt een aanzienlijk hoger beveiligingsniveau en is de aanbevolen standaard voor nieuwe en bestaande applicaties.
Configuratie
Controleer of onderstaande appSetting aanwezig is in de web.config en op true staat:
<add key="passwordstorage.use_pbkdf2" value="true" />
De instelling kan worden toegevoegd via Deployment AppSettings of rechtstreeks in de web.config.
Let op: wanneer de key via Deployment wordt toegevoegd, wordt deze niet automatisch vastgelegd in SVN. Indien configuratiebeheer via SVN gewenst is, moet de wijziging daar afzonderlijk worden gecommit.
Let op: deze instelling wordt naar verwachting in een toekomstige release standaard onderdeel van nieuwe applicaties. Omdat dit nog niet in de huidige 3.10-generatie is opgenomen, blijft controle en configuratie voorlopig onderdeel van iedere update.
Controlepunten
- Staat
passwordstorage.use_pbkdf2=trueingesteld? β Geen verdere actie nodig. - Ontbreekt de key of staat deze op
false? β De applicatie gebruikt nog MD5 en moet worden beoordeeld voor omzetting naar PBKDF2. - Is sprake van een CMS-website, oude NNetwork-website of veel authenticatieverkeer? β Eerst uitgebreider testen op een acceptatieomgeving.
Testen na de wijziging
- Log vooraf in om de huidige werking en prestaties vast te stellen.
- Voer de wijziging en eventuele update uit.
- Controleer of normaal kan worden ingelogd.
- Controleer de eerste Γ©n tweede login op mogelijke vertraging.
- Test relevante webservices, REST-endpoints en externe koppelingen.
- Leg de uitgevoerde controle vast bij de update of deployment.
Houd rekening met een mogelijk iets tragere eerste login. Dit is een normaal gevolg van de zwaardere hashingmethode. Daarna zouden de prestaties grotendeels op het gebruikelijke niveau moeten liggen.
Extra aandacht bij CMS en websites
Applicaties met een CMS, HCMS-website of oude NNetwork-website vereisen aanvullende controle.
Voor deze omgevingen geldt:
- Controleer vooraf of de gebruikte Framework- en CMS-componenten PBKDF2 ondersteunen.
- Gebruik voor wachtwoordvergelijkingen
matches()in plaats vanequals(). - Test CMS-gebruikers en websitefunctionaliteit expliciet.
- Voer de wijziging bij voorkeur eerst uit op een acceptatieomgeving.
Minimale versies
| Component | Minimale versie |
|---|---|
| Framework | 3.8-RC.C11128 |
| Plugin CMS Account | 92971 |
| Plugin CMS HTTP Component | 92968 |
| Novulo CMS | M3031 r1129 |
Aanvullende configuratie
De onderstaande key hoeft standaard niet te worden toegevoegd:
<add key="passwordstorage.hashiterationcount" value="120000" />
De waarde 120000 is reeds de standaardinstelling. Deze configuratie is uitsluitend bedoeld om het aantal iteraties eventueel te verlagen wanneer aantoonbare performanceproblemen optreden.
Samenvatting
Bij updates adviseren wij standaard te controleren of:
<add key="passwordstorage.use_pbkdf2" value="true" />
actief is.
Ontbreekt deze instelling of staat deze op false, dan gebruikt de applicatie nog MD5. Zorg in dat geval voor de benodigde configuratie en testen.
Door PBKDF2 toe te passen blijven applicaties voldoen aan de actuele beveiligingsstandaarden en voorkomen we dat nieuwe of bestaande omgevingen onbedoeld MD5 blijven gebruiken.
π¬π§ English
TL;DR
Is passwordstorage.use_pbkdf2=true present? Then youβre good.
Is the key missing or set to false? Then the application is still using MD5. Add the key and perform the required testing.
Pay extra attention to CMS websites, legacy NNetwork websites and applications with heavy web service traffic.
Why this change?
In line with our Information Security Best Practices, we recommend phasing out MD5 and using PBKDF2 for password storage.
MD5 is considered an outdated hashing algorithm and no longer complies with current security standards. PBKDF2 provides a significantly higher level of protection and is the recommended standard for both new and existing applications.
Configuration
Verify that the following appSetting exists in the web.config and is set to true:
<add key="passwordstorage.use_pbkdf2" value="true" />
The setting can be added through Deployment AppSettings or directly in the web.config.
Note: when the key is added through Deployment, it is not automatically committed to SVN. If configuration management through SVN is required, commit the change separately.
Note: this setting is expected to become part of the default configuration for new applications in a future release. Since it is not yet included in the current 3.10 generation, validation and configuration remain part of every update process.
Validation Checklist
- Is
passwordstorage.use_pbkdf2=trueenabled? β No further action required. - Is the key missing or set to
false? β The application is still using MD5 and should be evaluated for migration to PBKDF2. - Is the application using a CMS website, legacy NNetwork website, or handling large amounts of authentication traffic? β Perform additional testing in an acceptance environment first.
Testing After the Change
- Log in before making the change to establish a baseline.
- Apply the configuration change and update.
- Verify that login still works as expected.
- Check both the first and second login for potential performance impact.
- Test web services, REST endpoints and external integrations.
- Document the validation performed during the update.
A slightly slower first login is expected due to the stronger hashing mechanism. Performance should largely normalize afterwards.
Additional Attention for CMS and Websites
Applications using CMS, HCMS websites or legacy NNetwork websites require additional validation.
For these environments:
- Verify that Framework and CMS components support PBKDF2.
- Use
matches()instead ofequals()when comparing passwords. - Explicitly test CMS users and website functionality.
- Preferably perform the change in an acceptance environment first.
Minimum Supported Versions
| Component | Minimum Version |
|---|---|
| Framework | 3.8-RC.C11128 |
| CMS Account Plugin | 92971 |
| CMS HTTP Component Plugin | 92968 |
| Novulo CMS | M3031 r1129 |
Additional Configuration
The following key is normally not required:
<add key="passwordstorage.hashiterationcount" value="120000" />
120000 is already the default value. This setting should only be used when there is a proven need to lower the number of iterations because of performance constraints.
Summary
As part of every update, verify that:
<add key="passwordstorage.use_pbkdf2" value="true" />
is active.
If the key is missing or set to false, the application is still using MD5 and should be reviewed for migration to PBKDF2.
Adopting PBKDF2 helps ensure compliance with current security standards and prevents new or existing environments from continuing to use legacy MD5 password hashing.