DataPower

DataPower

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Hashing Algorithm Verification

    Posted Mon December 12, 2022 08:21 AM
    Hi All,

      We are using the physical box of DPGW v 10.0.4.0, a question raised by information security to share the evidence of the Hashing Algorithm used by DPGW. Can someone please support that where can we find the evidence for it, 


  • 2.  RE: Hashing Algorithm Verification

    Posted Mon December 12, 2022 09:15 AM
    Your question is a little vague, but I'm assuming you're asking about what hashing algorithm is used to hash login  passwords before storing them?
    If so, please consult the help for RBM Settings. and then look for the password hash algorithm - https://www.ibm.com/docs/en/datapower-gateway/10.0.1?topic=commands-password-hash-algorithm

    ------------------------------
    Charlie Sumner
    ------------------------------



  • 3.  RE: Hashing Algorithm Verification

    Posted Mon December 12, 2022 09:25 AM
    Thanks Charlie,

    I appreciate your quick response....

    Below is the request raised by Information Security and as an administrator we need to submit screenshots to respective teams. Please suggest accordingly
    ----------------------------------
    "3.12 SHA-2 (SHA 256,SHA-512) must be used as a standard hashing algorithm to ensure message integrity (PCI DSS 3.4)"
    ------------------------------

    ------------------------------
    Kashif Qadeer
    ------------------------------