# Password Hashing Update: MD5 =\> PBKDF2

**URL:** <https://community.novulo.com/t/password-hashing-update-md5-pbkdf2/976>\
**Category:** Wiki\
**Created:** [October 5, 2026, 10:40am UTC](https://community.novulo.com/t/password-hashing-update-md5-pbkdf2/976 "2026-10-05T10:40:12Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rose](https://yyz2.discourse-cdn.com/flex008/user_avatar/community.novulo.com/rose/32/4_2.png) [@Rose](https://community.novulo.com/u/Rose)\
**Post date:** [October 5, 2026, 10:40am UTC](https://community.novulo.com/t/password-hashing-update-md5-pbkdf2/976/1 "2026-10-05T10:40:12Z")

</div>

# Password Hashing Update: MD5 → PBKDF2

Select your preferred language:

- 🇳🇱 Dutch: open the first section
- 🇬🇧 English: open the second section

> **🇳🇱 Nederlands**
>
> ## TL;DR
> 
> ✅ `passwordstorage.use_pbkdf2=true` aanwezig? Dan is het goed.
> 
> ❌ Key ontbreekt of staat op `false`? Dan gebruikt de applicatie nog MD5. Voeg de key toe en voer de benodigde testen uit.
> 
> ⚠ Extra aandacht voor CMS-websites, oude NNetwork-websites en applicaties met veel webserviceverkeer.
> 
> * * *
> 
> ## Waarom deze wijziging?
> 
> Conform onze Information Security Best Practices adviseren we om MD5 uit te faseren en gebruik te maken van PBKDF2 voor wachtwoordopslag.
> 
> MD5 wordt beschouwd als een verouderde hashingmethode en voldoet niet meer aan actuele beveiligingsrichtlijnen. PBKDF2 biedt een aanzienlijk hoger beveiligingsniveau en is de aanbevolen standaard voor nieuwe en bestaande applicaties.
> 
> ## Configuratie
> 
> Controleer of onderstaande appSetting aanwezig is in de `web.config` en op `true` staat:
> 
> ```xml
> <add key="passwordstorage.use_pbkdf2" value="true" />
> 
> ```
> 
> De instelling kan worden toegevoegd via **Deployment AppSettings** of rechtstreeks in de **web.config**.
> 
> > Let op: wanneer de key via Deployment wordt toegevoegd, wordt deze niet automatisch vastgelegd in SVN. Indien configuratiebeheer via SVN gewenst is, moet de wijziging daar afzonderlijk worden gecommit.
> 
> > Let op: deze instelling wordt naar verwachting in een toekomstige release standaard onderdeel van nieuwe applicaties. Omdat dit nog niet in de huidige 3.10-generatie is opgenomen, blijft controle en configuratie voorlopig onderdeel van iedere update.
> 
> ## Controlepunten
> 
> - Staat `passwordstorage.use_pbkdf2=true` ingesteld? → Geen verdere actie nodig.
> - Ontbreekt de key of staat deze op `false`? → De applicatie gebruikt nog MD5 en moet worden beoordeeld voor omzetting naar PBKDF2.
> - Is sprake van een CMS-website, oude NNetwork-website of veel authenticatieverkeer? → Eerst uitgebreider testen op een acceptatieomgeving.
> 
> ## Testen na de wijziging
> 
> 1. Log vooraf in om de huidige werking en prestaties vast te stellen.
> 2. Voer de wijziging en eventuele update uit.
> 3. Controleer of normaal kan worden ingelogd.
> 4. Controleer de eerste én tweede login op mogelijke vertraging.
> 5. Test relevante webservices, REST-endpoints en externe koppelingen.
> 6. Leg de uitgevoerde controle vast bij de update of deployment.
> 
> Houd rekening met een mogelijk iets tragere eerste login. Dit is een normaal gevolg van de zwaardere hashingmethode. Daarna zouden de prestaties grotendeels op het gebruikelijke niveau moeten liggen.
> 
> ## Extra aandacht bij CMS en websites
> 
> Applicaties met een CMS, HCMS-website of oude NNetwork-website vereisen aanvullende controle.
> 
> Voor deze omgevingen geldt:
> 
> - Controleer vooraf of de gebruikte Framework- en CMS-componenten PBKDF2 ondersteunen.
> - Gebruik voor wachtwoordvergelijkingen `matches()` in plaats van `equals()`.
> - Test CMS-gebruikers en websitefunctionaliteit expliciet.
> - Voer de wijziging bij voorkeur eerst uit op een acceptatieomgeving.
> 
> ### Minimale versies
> 
> | Component | Minimale versie |
> | --- | --- |
> | Framework | 3.8-RC.C11128 |
> | Plugin CMS Account | 92971 |
> | Plugin CMS HTTP Component | 92968 |
> | Novulo CMS | M3031 r1129 |
> 
> ## Aanvullende configuratie
> 
> De onderstaande key hoeft standaard **niet** te worden toegevoegd:
> 
> ```xml
> <add key="passwordstorage.hashiterationcount" value="120000" />
> 
> ```
> 
> De waarde `120000` is reeds de standaardinstelling. Deze configuratie is uitsluitend bedoeld om het aantal iteraties eventueel te verlagen wanneer aantoonbare performanceproblemen optreden.
> 
> ## Samenvatting
> 
> Bij updates adviseren wij standaard te controleren of:
> 
> ```xml
> <add key="passwordstorage.use_pbkdf2" value="true" />
> 
> ```
> 
> actief is.
> 
> Ontbreekt deze instelling of staat deze op `false`, dan gebruikt de applicatie nog MD5. Zorg in dat geval voor de benodigde configuratie en testen.
> 
> Door PBKDF2 toe te passen blijven applicaties voldoen aan de actuele beveiligingsstandaarden en voorkomen we dat nieuwe of bestaande omgevingen onbedoeld MD5 blijven gebruiken.

> **🇬🇧 English**
>
> ## TL;DR
> 
> ✅ Is `passwordstorage.use_pbkdf2=true` present? Then you’re good.
> 
> ❌ Is the key missing or set to `false`? Then the application is still using MD5. Add the key and perform the required testing.
> 
> ⚠ Pay extra attention to CMS websites, legacy NNetwork websites and applications with heavy web service traffic.
> 
> * * *
> 
> ## Why this change?
> 
> In line with our Information Security Best Practices, we recommend phasing out MD5 and using PBKDF2 for password storage.
> 
> MD5 is considered an outdated hashing algorithm and no longer complies with current security standards. PBKDF2 provides a significantly higher level of protection and is the recommended standard for both new and existing applications.
> 
> ## Configuration
> 
> Verify that the following appSetting exists in the `web.config` and is set to `true`:
> 
> ```xml
> <add key="passwordstorage.use_pbkdf2" value="true" />
> 
> ```
> 
> The setting can be added through **Deployment AppSettings** or directly in the **web.config**.
> 
> > Note: when the key is added through Deployment, it is not automatically committed to SVN. If configuration management through SVN is required, commit the change separately.
> 
> > Note: this setting is expected to become part of the default configuration for new applications in a future release. Since it is not yet included in the current 3.10 generation, validation and configuration remain part of every update process.
> 
> ## Validation Checklist
> 
> - Is `passwordstorage.use_pbkdf2=true` enabled? → No further action required.
> - Is the key missing or set to `false`? → The application is still using MD5 and should be evaluated for migration to PBKDF2.
> - Is the application using a CMS website, legacy NNetwork website, or handling large amounts of authentication traffic? → Perform additional testing in an acceptance environment first.
> 
> ## Testing After the Change
> 
> 1. Log in before making the change to establish a baseline.
> 2. Apply the configuration change and update.
> 3. Verify that login still works as expected.
> 4. Check both the first and second login for potential performance impact.
> 5. Test web services, REST endpoints and external integrations.
> 6. Document the validation performed during the update.
> 
> A slightly slower first login is expected due to the stronger hashing mechanism. Performance should largely normalize afterwards.
> 
> ## Additional Attention for CMS and Websites
> 
> Applications using CMS, HCMS websites or legacy NNetwork websites require additional validation.
> 
> For these environments:
> 
> - Verify that Framework and CMS components support PBKDF2.
> - Use `matches()` instead of `equals()` when comparing passwords.
> - Explicitly test CMS users and website functionality.
> - Preferably perform the change in an acceptance environment first.
> 
> ### Minimum Supported Versions
> 
> | Component | Minimum Version |
> | --- | --- |
> | Framework | 3.8-RC.C11128 |
> | CMS Account Plugin | 92971 |
> | CMS HTTP Component Plugin | 92968 |
> | Novulo CMS | M3031 r1129 |
> 
> ## Additional Configuration
> 
> The following key is normally **not required** :
> 
> ```xml
> <add key="passwordstorage.hashiterationcount" value="120000" />
> 
> ```
> 
> `120000` is already the default value. This setting should only be used when there is a proven need to lower the number of iterations because of performance constraints.
> 
> ## Summary
> 
> As part of every update, verify that:
> 
> ```xml
> <add key="passwordstorage.use_pbkdf2" value="true" />
> 
> ```
> 
> is active.
> 
> If the key is missing or set to `false`, the application is still using MD5 and should be reviewed for migration to PBKDF2.
> 
> Adopting PBKDF2 helps ensure compliance with current security standards and prevents new or existing environments from continuing to use legacy MD5 password hashing.
