Hi Lena and Christian,

Thank you for your input and for pointing out that this functionality
will "naturally" be available in 26.04 once upstream provides it.

I would kindly like to ask for your support regarding one point: since
using PBKDF2 with a configurable number of iterations is quite important
for meeting security requirements (including in some cases FIPS 140-3),
do you think it would be possible to introduce this option also in
Ubuntu 24.04 (perhaps via a maintenance update)?

Best regards,

Filippo

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to openldap in Ubuntu.
https://bugs.launchpad.net/bugs/2125685

Title:
  pbkdf2 module not make iterations configurable and FIPS 140-3

Status in openldap package in Ubuntu:
  Confirmed
Status in openldap source package in Jammy:
  Confirmed
Status in openldap source package in Noble:
  Confirmed
Status in openldap source package in Plucky:
  Confirmed
Status in openldap source package in Questing:
  Confirmed

Bug description:
  On Ubuntu 24.04, the OpenLDAP package ships with the library 
/usr/lib/ldap/pw-pbkdf2.so.
  While this module works for generating PBKDF2-SHA512 password hashes, it does 
not provide an option to configure the number of iterations.

  For example:
  slappasswd -o module-load=pw-pbkdf2.so -h {PBKDF2-SHA512}

  generates a hash with a fixed iteration count (e.g. 10000) and does
  not accept parameters to increase it.

  In contrast, the upstream contrib module passwd/pbkdf2 on
  https://git.openldap.org/openldap/openldap/-/tree/master/contrib/slapd-
  modules/passwd/pbkdf2

  supports the iteration count option and allows administrators to
  configure it.

  moduleload pw-pbkdf2.so [iterations]

  Steps to reproduce:

  Install OpenLDAP on Ubuntu 24.04. (slapd and slapd-contrib pakages)
  Run
  slappasswd -o module-load=pw-pbkdf2.la -h {PBKDF2} -s secret
  {PBKDF2}10000$ZvU8GRSybbefW48n8BeyuA$XE1t4W09ZP0z8zmLVb/SbwaOl2Y

  Expected behavior:
  The pw-pbkdf2.so module should support configuration of the iteration count, 
as provided in the upstream passwd/pbkdf2 contrib module.

  Actual behavior:
  Iteration count is hardcoded (default: 10000), and cannot be changed.

  Impact:
  Without the ability to configure the iteration count, it is not possible to 
meet current security best practices or achieve compliance with FIPS 140-3, 
which requires configurable and sufficiently high iteration counts for PBKDF2.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openldap/+bug/2125685/+subscriptions


-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to