Build: #2733 was successful Scheduled with changes by Guus der Kinderen

Stages & jobs

  1. Build and Package

  2. Copy to Website

Build result summary

Details

Completed
Queue duration
1 second
Duration
15 minutes
Labels
None
Revision
37847f59ecf08bbe7e3b0961025aedc84d473d46
Total tests
2002
Successful since
#2725 ()

Tests

Code commits

Author Commit Message Commit date
Guus der Kinderen Guus der Kinderen a3f388203cb9acf38eb29acb92bf92a27d19b405 OF-3257/OF-3258 (code review): Spelling: 'nonexisting' -> 'nonexistent'
Guus der Kinderen Guus der Kinderen 37847f59ecf08bbe7e3b0961025aedc84d473d46 OF-3257/OF-3258 (code review): Prevent order-dependent failures by resetting the property after each test.
Guus der Kinderen Guus der Kinderen 392149534185eac2a45bd1fddccb9802a83daac1 OF-3258 (code review): remove redundant whitespace
Guus der Kinderen Guus der Kinderen dd49e6f4a72e153e70fbdf723013f98022e44ef6 OF-3258: Guard against user enumeration in ScramSha1SaslServer
This replaces the use of randomly generated salts for unknown users with a deterministic but cryptographically unpredictable value derived from the username and a server-side secret.

Prior to this change, a non-deterministic salt was used, which can be used (by retrieving it more than once) to determine if a user exists.
Guus der Kinderen Guus der Kinderen 8ef647a8c44b1e74cc805662df3463b72b73f97b OF-3257/OF-3258 (code review): Guard against empty values for server secret constant
Having an empty value for the server secret value is unlikely to happen, but should be replaced. This is an easy hardening with no downside.

Jira issues

IssueDescriptionStatus
Unknown Issue TypeOF-3257Could not obtain issue details from Jira
Unknown Issue TypeOF-3258Could not obtain issue details from Jira

Shared artifacts

Artifact File size
.deb files 68 MB