Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-27 Thread Gabriel Sánchez Martínez
> On Sep 26, 2014, at 17:03, Mark Thomas wrote: > > On 26/09/2014 16:45, Christopher Schultz wrote: > >>> +1 for commit. >> >> Are you up for back-porting this to Tomcat 7? > > Hmm. Not sure at this point. I'd like to give it sometime to settle in > to 8.0.x first. I understand wanting to w

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-26 Thread Mark Thomas
On 26/09/2014 16:45, Christopher Schultz wrote: >> +1 for commit. > > Are you up for back-porting this to Tomcat 7? Hmm. Not sure at this point. I'd like to give it sometime to settle in to 8.0.x first. > I noticed that you > committed to trunk in smaller pieces rather than a single commit. Was

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-26 Thread Christopher Schultz
Mark, On 9/25/14 9:18 AM, Christopher Schultz wrote: > Mark, > > On 9/24/14 12:27 PM, Mark Thomas wrote: >> On 24/09/2014 16:59, Christopher Schultz wrote: >>> Mark, >>> >>> On 9/24/14 5:00 AM, Mark Thomas wrote: On 23/09/2014 10:49, Mark Thomas wrote: > On 23/09/2014 00:56, "Gabriel E.

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-25 Thread Christopher Schultz
Mark, On 9/24/14 12:27 PM, Mark Thomas wrote: > On 24/09/2014 16:59, Christopher Schultz wrote: >> Mark, >> >> On 9/24/14 5:00 AM, Mark Thomas wrote: >>> On 23/09/2014 10:49, Mark Thomas wrote: On 23/09/2014 00:56, "Gabriel E. Sánchez Martínez" wrote: > > On 09/17/2014 04:36 AM, Mark

Re: Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-24 Thread Gabriel E. Sánchez Martínez
On 09/24/2014 12:27 PM, Mark Thomas wrote: On 24/09/2014 16:59, Christopher Schultz wrote: Mark, On 9/24/14 5:00 AM, Mark Thomas wrote: On 23/09/2014 10:49, Mark Thomas wrote: On 23/09/2014 00:56, "Gabriel E. Sánchez Martínez" wrote: On 09/17/2014 04:36 AM, Mark Thomas wrote: On 16/09/2014

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-24 Thread Mark Thomas
On 24/09/2014 16:59, Christopher Schultz wrote: > Mark, > > On 9/24/14 5:00 AM, Mark Thomas wrote: >> On 23/09/2014 10:49, Mark Thomas wrote: >>> On 23/09/2014 00:56, "Gabriel E. Sánchez Martínez" wrote: On 09/17/2014 04:36 AM, Mark Thomas wrote: > On 16/09/2014 22:14, Christopher Sc

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-24 Thread Christopher Schultz
Mark, On 9/24/14 5:00 AM, Mark Thomas wrote: > On 23/09/2014 10:49, Mark Thomas wrote: >> On 23/09/2014 00:56, "Gabriel E. Sánchez Martínez" wrote: >>> >>> On 09/17/2014 04:36 AM, Mark Thomas wrote: On 16/09/2014 22:14, Christopher Schultz wrote: > Mark, > > On 9/16/14 3:39 PM, Ma

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-24 Thread Mark Thomas
On 23/09/2014 10:49, Mark Thomas wrote: > On 23/09/2014 00:56, "Gabriel E. Sánchez Martínez" wrote: >> >> On 09/17/2014 04:36 AM, Mark Thomas wrote: >>> On 16/09/2014 22:14, Christopher Schultz wrote: Mark, On 9/16/14 3:39 PM, Mark Thomas wrote: > Updated patch: > http://peop

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-23 Thread Felix Schumacher
Am 23.09.2014 um 19:35 schrieb Felix Schumacher: Am 23.09.2014 um 01:56 schrieb "Gabriel E. Sánchez Martínez": On 09/17/2014 04:36 AM, Mark Thomas wrote: On 16/09/2014 22:14, Christopher Schultz wrote: Mark, On 9/16/14 3:39 PM, Mark Thomas wrote: Updated patch: http://people.apache.org/~mar

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-23 Thread Felix Schumacher
Am 23.09.2014 um 01:56 schrieb "Gabriel E. Sánchez Martínez": On 09/17/2014 04:36 AM, Mark Thomas wrote: On 16/09/2014 22:14, Christopher Schultz wrote: Mark, On 9/16/14 3:39 PM, Mark Thomas wrote: Updated patch: http://people.apache.org/~markt/patches/2014-09-16-bug56403-tc8-v2.patch It'

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-23 Thread Felix Schumacher
Am 17.09.2014 um 10:36 schrieb Mark Thomas: On 16/09/2014 22:14, Christopher Schultz wrote: Mark, On 9/16/14 3:39 PM, Mark Thomas wrote: Updated patch: http://people.apache.org/~markt/patches/2014-09-16-bug56403-tc8-v2.patch Looks good, but its missing a configuration for the digester to actu

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-23 Thread Christopher Schultz
Gabriel, On 9/22/14 7:56 PM, "Gabriel E. Sánchez Martínez" wrote: > > On 09/17/2014 04:36 AM, Mark Thomas wrote: >> On 16/09/2014 22:14, Christopher Schultz wrote: >>> Mark, >>> >>> On 9/16/14 3:39 PM, Mark Thomas wrote: Updated patch: http://people.apache.org/~markt/patches/2014-09-16-

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-23 Thread Mark Thomas
On 23/09/2014 00:56, "Gabriel E. Sánchez Martínez" wrote: > > On 09/17/2014 04:36 AM, Mark Thomas wrote: >> On 16/09/2014 22:14, Christopher Schultz wrote: >>> Mark, >>> >>> On 9/16/14 3:39 PM, Mark Thomas wrote: Updated patch: http://people.apache.org/~markt/patches/2014-09-16-bug56403-

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-22 Thread Gabriel E. Sánchez Martínez
On 09/17/2014 04:36 AM, Mark Thomas wrote: On 16/09/2014 22:14, Christopher Schultz wrote: Mark, On 9/16/14 3:39 PM, Mark Thomas wrote: Updated patch: http://people.apache.org/~markt/patches/2014-09-16-bug56403-tc8-v2.patch It's looking good! Looks good, but its missing a configuration for

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-17 Thread Mark Thomas
On 16/09/2014 22:14, Christopher Schultz wrote: > Mark, > > On 9/16/14 3:39 PM, Mark Thomas wrote: >> Updated patch: >> http://people.apache.org/~markt/patches/2014-09-16-bug56403-tc8-v2.patch > > Looks good, but its missing a configuration for the digester to actually > read the configuration an

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-16 Thread Christopher Schultz
Mark, On 9/16/14 3:39 PM, Mark Thomas wrote: > Updated patch: > http://people.apache.org/~markt/patches/2014-09-16-bug56403-tc8-v2.patch Looks good, but its missing a configuration for the digester to actually read the configuration and set-up the CredentialHandler objects at runtime. Existing Me

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-16 Thread Christopher Schultz
Mark, On 9/16/14 3:39 PM, Mark Thomas wrote: > On 16/09/2014 16:20, Christopher Schultz wrote: >> 1. In terms of limiting converting to String values, we could base >> everything on byte[] instead of String. > > Having looked at the current code and the Servlet API I don't believe > that this is

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-16 Thread Christopher Schultz
Mark, On 9/16/14 12:46 PM, Mark Thomas wrote: > On 16/09/2014 17:17, Mark Thomas wrote: >> On 16/09/2014 16:20, Christopher Schultz wrote: > >>> 2. I don't like CredentialHandler.mutate(String input, byte[] salt, int >>> iterations). I think it ties the method signature to the implementation >>>

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-16 Thread Mark Thomas
On 16/09/2014 16:20, Christopher Schultz wrote: > 1. In terms of limiting converting to String values, we could base > everything on byte[] instead of String. Having looked at the current code and the Servlet API I don't believe that this is practical. > 2. I don't like CredentialHandler.mutate(

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-16 Thread Mark Thomas
On 16/09/2014 16:20, Christopher Schultz wrote: > StringBuilder credential = new StringBuilder(saltLength << 1 + > serverCredential.length() + 10 + 2); > credential.append(HexUtils.toString(salt)) > .append('$') > .append(iterations) > .append('$') >

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-16 Thread Mark Thomas
On 16/09/2014 17:17, Mark Thomas wrote: > On 16/09/2014 16:20, Christopher Schultz wrote: >> 2. I don't like CredentialHandler.mutate(String input, byte[] salt, int >> iterations). I think it ties the method signature to the implementation >> of the mutation algorithm. PBKDF2 for instance has both

Re: Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-16 Thread Mark Thomas
On 16/09/2014 16:20, Christopher Schultz wrote: > All, > > In reference to bug 56403 > (https://issues.apache.org/bugzilla/show_bug.cgi?id=56403) and > specifically markt's proposed patch > (http://people.apache.org/~markt/patches/2014-09-16-bug56403-tc8-v1.patch), > I have the following comments.

Discussion of pluggable password-derivation in Realms [Bug 56403]

2014-09-16 Thread Christopher Schultz
All, In reference to bug 56403 (https://issues.apache.org/bugzilla/show_bug.cgi?id=56403) and specifically markt's proposed patch (http://people.apache.org/~markt/patches/2014-09-16-bug56403-tc8-v1.patch), I have the following comments. I'm interested in what others have to say. 1. In terms of l