Bỏ qua để đến Nội dung
Menu
Câu hỏi này đã bị gắn cờ
2 Trả lời
9603 Lượt xem

Are passwords now encrypted by default in version 7?

I have read many places that a mod needs to be installed for the passwords to be encrypted but they were for version 6.

If I need to install a mod, what is it called? I have only found "Password Encryption" but I think that is for email only?

Please advise, I am very new to OpenERP and want to make it secure.

Ảnh đại diện
Huỷ bỏ
Câu trả lời hay nhất

Please, search before post new answer. This is a common question: https://accounts.openerp.com/forum/Help-1/question/6545

Ảnh đại diện
Huỷ bỏ
Câu trả lời hay nhất

Just checked with my 7.0 installation and the passwords are not encrypted. However, I wonder what security problem you are worried about? Encrypted passwords in the database only mean that somebody who connects directly to your db, or who gets access to a database dump can't see the user passwords (which is of course a good thing in itself). Access to the database and its dumps should be restricted as there is far more than just user passwords that is potentially sensitive information in an ERP. Password encryption does not increase the security of the application in any way.

If you are worried about the general security of OpenERP that are other more important things to be concerned about, such only allowing connections to your OpenERP server using SSL.

Ảnh đại diện
Huỷ bỏ

For one thing, it means that if a server is compromised as you described, if users have used the same passwords elsewhere, their accounts everywhere else haven't been compromised too...

Bài viết liên quan Trả lời Lượt xem Hoạt động
2
thg 2 21
17391
2
thg 3 15
3834
1
thg 4 24
26623
0
thg 12 24
9587
0
thg 5 25
1601