Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Estate Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Pricing
  • Help

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Accounting
  • Inventory
  • PoS
  • Project
  • MRP
All apps
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
Help

Why does OpenERP store passwords in plain text by default

Subscribe

Get notified when there's activity on this post

This question has been flagged
securityv7
4 Replies
10190 Views
Avatar
IBS Group

I would like to hear some input from the Dev team.

4
Avatar
Discard
Obay Albadri

Check this: http://help.openerp.com/question/6545/does-openerp-store-passwords-in-clear-text/

IBS Group
Author

Yes I saw, my question is slightly different than that one :)

Obay Albadri

Yes it is, i am waiting for explanation too. :)

hiren

For me more crucially, why is communication using xmlrpc and not xmlrpcs by default? The nature of openerp is that it houses businesses core data, it should by nature think of security first. Users passwords are also not checked for complexity, users can happily use passwords123 in openerp, for business use, that's bad.

Avatar
Fabien Pinckaers (fp)
Best Answer

The real reason is historical. We never thought "ok, it's a good idea to not encrypt password by default".

We implemented the plain password XML-RPC auth as it was the fastest implementation back in 2005, when our priority was to deliver our direct implementation customers asap. (and we didn't had extra budget at that time to implement several auth methods).

Since then, we have added encryption as a module "auth_crypt" as well as other authentification mechanisms; ldap, openid, oauth, etc. Every authentification mechanism is implemented by a specific module. We supplied them as optionnal modules so that everyone can choose the one he needs. We did not installed base_crypt by default as it's implementation was not compatible with ldap. (I do not know if it's still the case)

I guess we did not changed the default mode because: 1/ there is always something more important to do (the todo was trapped in the daily flow of things to do), 2/ it would have broken compatibilities for existing customers. 3/ base_crypt was not compatible with auth_ldap (but I think this should be fixed now)

Since the point 2 is not a problem anymore as we have a good migration service now, we should change the default the encrypted password in the next version.

Can anyone propose a merge proposal on the trunk branch to change the default?

7
Avatar
Discard
IBS Group
Author

Thank you for the thorough explanation.

Avatar
Brian Dunnette
Best Answer

The OpenERP developers have justified the use of plain-text passwords as a password-recovery measure:

"As for the reason for cleartext passwords: once you switch to encrypted passwords you can't recover user passwords anymore. So enabling it is a choice, because there's no going back. We don't currently plan to make passwords encrypted by default."

(from OpenERP bug #738721)

1
Avatar
Discard
Avatar
Gustavo
Best Answer

I see the point in the question, IMHO as long as you protect the PostgreSQL database and root users, you are going to be fine from a security standpoint. It's not perfect, but I would enforce security at the server level instead of the appĺication level

1
Avatar
Discard
Avatar
Francesco OpenCode
Best Answer

If you want you can install module auth_crypt (standard OpenERP module) to crypt your passwords but, after this, you can't recovery them. You can choose!

0
Avatar
Discard
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Sign up
Related Posts Replies Views Activity
Creating user groups that allow users to access several companies
security v7
Avatar
Avatar
1
Feb 25
8554
Aps menu request access to apps.openerp.com
security v7
Avatar
Avatar
1
Mar 15
6408
Settings to session timeout? Solved
security v7 session
Avatar
Avatar
17
Apr 24
59232
Permission for a group to edit a single field only? Solved
security v7 groups
Avatar
Avatar
Avatar
Avatar
Avatar
10
Dec 23
37740
Why there is not timeout period - session/connection to expire in OpenERP? Solved
security v7 connection
Avatar
Avatar
2
Jun 20
25872
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now