An admin noticed that their machine had a 70% cpu increase with pbkdf2 binds. This is likely related to the time cap being too large, and the minimal threshold being too high especially given the nss impl bug.
We should consider lowering the time amount and minimal cap to help ease people into this scheme. Today, even pbkdf2 at 1024 rounds is better than what we have today in ssha512.
Metadata Update from @firstyear: - Issue assigned to firstyear
Do I dare suggest making it configurable? I do :-p just a suggestion, not a hard request.
Metadata Update from @mreynolds: - Custom field component adjusted to None - Custom field origin adjusted to None - Custom field reviewstatus adjusted to None - Custom field type adjusted to None - Custom field version adjusted to None
I knew someone would say it ;)
I still want to avoid configuration of this, I think we should be able to get it "right" because most people won't touch it - they'll set and forget, and they'll never make it better again,
I think the issue is we just need to be more conservative instead while the issue in NSS exists.
<img alt="0001-Ticket-49387-pbkdf2-settings-were-too-aggressive.patch" src="/389-ds-base/issue/raw/files/dcb804622ee5fb5606ddd03ee59c609288c658587dfa48b7b2260e9e93855302-0001-Ticket-49387-pbkdf2-settings-were-too-aggressive.patch" />
Metadata Update from @firstyear: - Custom field reviewstatus adjusted to review (was: None)
It looks good, ack
Metadata Update from @mreynolds: - Custom field reviewstatus adjusted to ack (was: review)
commit ee25b88 To ssh://git@pagure.io/389-ds-base.git 805e8f4..ee25b88 master -> master
Metadata Update from @firstyear: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
@firstyear - should this also go into 1.3.7?
389-ds-base is moving from Pagure to Github. This means that new issues and pull requests will be accepted only in 389-ds-base's github repository.
This issue has been cloned to Github and is available here: - https://github.com/389ds/389-ds-base/issues/2446
If you want to receive further updates on the issue, please navigate to the github issue and click on subscribe button.
subscribe
Thank you for understanding. We apologize for all inconvenience.
Metadata Update from @spichugi: - Issue close_status updated to: wontfix (was: fixed)
Login to comment on this ticket.