Skip to content

Add pbkdf2-sha256 as a FIPS 140 approved password hashing algorithm - #2295

Closed
iAbhishek91 wants to merge 1 commit into
drakkan:mainfrom
iAbhishek91:feat/pbkdf2-sha256-password-hashing
Closed

iAbhishek91 wants to merge 1 commit into
drakkan:mainfrom
iAbhishek91:feat/pbkdf2-sha256-password-hashing

Conversation

@iAbhishek91

Copy link
Copy Markdown

Summary

Closes #2294.

password_hashing.algo currently only supports bcrypt and
argon2id, neither of which is a NIST/FIPS 140 approved algorithm.
This prevents building a FIPS-compliant SFTPGo image, since there's
no FIPS-approved algorithm to select even with a FIPS-enabled Go
toolchain.

This PR adds pbkdf2-sha256 (PBKDF2-HMAC-SHA256, per NIST SP 800-132)
as a third selectable value for password_hashing.algo, plus a new
password_hashing.pbkdf2_options.iterations setting (default
600000, minimum enforced 10000 per NIST SP 800-132).

SFTPGo already implements PBKDF2 verification, used for migrating
password hashes from other systems (comparePbkdf2PasswordAndHash,
supporting $pbkdf2-b64salt-sha256$, $pbkdf2-sha256$,
$pbkdf2-sha512$, $pbkdf2-sha1$). This change reuses that existing
verification path for the new pbkdf2-sha256 creation option, instead
of adding a parallel implementation.

Changes

  • internal/dataprovider/dataprovider.go: add HashingAlgoPBKDF2SHA256
    constant and Pbkdf2Options config struct; hashPlainPassword now
    creates a $pbkdf2-b64salt-sha256$<iterations>$<salt>$<hash> hash
    when selected, using util.GenerateRandomBytes for the salt and the
    existing pbkdf2SHA256B64SaltPrefix format so it round-trips through
    the existing comparePbkdf2PasswordAndHash verifier unchanged;
    initializeHashingAlgo validates the configured iteration count.
  • internal/config/config.go: default pbkdf2_options.iterations to
    600000 and register the corresponding viper default.
  • internal/dataprovider/admin.go, apikey.go, share.go: these
    duplicated the bcrypt/argon2id branching for hashing admin passwords,
    API keys and share passwords. Replaced with a call to the shared
    hashPlainPassword helper so all four credential types pick up
    pbkdf2-sha256 consistently, and added the matching
    comparePbkdf2PasswordAndHash branch to each type's verification
    path (previously only dataprovider.go's user-password verification
    handled pbkdf2 hashes; admin/API key/share verification assumed
    bcrypt-or-argon2id).

This is intentionally scoped to just the hashing algorithm; it doesn't
touch transport/TLS crypto, which is a separate FIPS concern already
addressed by building with a FIPS-enabled Go toolchain
(GOEXPERIMENT=boringcrypto), as noted in #1272.

Test plan

  • go build ./...
  • go vet ./internal/dataprovider/... ./internal/config/...
  • gofmt -l on all changed files (no output)
  • Manually verified hash/verify round-trip for pbkdf2-sha256
    (correct password matches, wrong password is rejected, hash has
    the expected $pbkdf2-b64salt-sha256$ format) with a local test;
    removed before submitting since this package has no existing
    test file to extend
  • Would appreciate maintainer guidance on whether a
    dataprovider_test.go should be introduced for this, since none
    currently exists in this package

SFTPGo currently only creates password hashes using bcrypt and
argon2id, neither of which is a NIST/FIPS 140 approved algorithm.
This blocks building FIPS-compliant SFTPGo images (see the FIPS
build discussion in drakkan#1272).

SFTPGo already implements PBKDF2 verification for migrating
passwords from other systems (comparePbkdf2PasswordAndHash), so
this change reuses that code and adds pbkdf2-sha256 (PBKDF2-HMAC-SHA256,
NIST SP 800-132) as a third selectable value for password_hashing.algo,
alongside a pbkdf2_options.iterations setting (default 600000,
minimum enforced 10000).

Admin, API key and share password hashing/verification, which
duplicated the bcrypt/argon2id branching, now call the shared
hashPlainPassword helper so all four credential types support the
new algorithm consistently.
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@drakkan

drakkan commented Sep 22, 2026

Copy link
Copy Markdown
Owner

see #2294 (comment). Thanks anyway

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature request: FIPS 140 approved password hashing algorithm (pbkdf2-sha256)

3 participants