Understanding the ForgeRock Password Storage Scheme (2024)
fusionauth.io·4d·
Discuss: Hacker News
🔓Password Cracking
Preview
Report Post

You have been charged with migrating your authentication system from ForgeRock to another platform. How do you move the users without knowing the users’ passwords or making them reset their passwords in the new system?

The short answer is “move the password hash”. In this post you will learn what a password hash is, how ForgeRock stores them and how to use this to transparently and safely migrate your users’ credentials.

What Is Password Hashing?

Password hashing might be a scary phrase. It sounds complicated and high-tech. In truth, the nitty-gritty details can be.

But don’t fret. The good news is that for the purposes of this post you can think of it in simple terms. Password hashing is taking a string of characters, applying an algorithm (or function), and coming up wit…

Similar Posts

Loading similar posts...