Encryption / Decryption ASP.NET MembershipProvider

I have some questions about the .Net membership package that I could not find clear answers.

  • What type of encryption is used, AES?
  • EncryptPassword method, can it handle any salt, or just add this before passing it?
  • DecryptPassword method - can you really decrypt the password? Isn't that such a bad practice?

Thanks for entering!

+5
source share
1 answer

add an item for providers for membership (ASP.NET settings diagram)

  • enablePasswordRetrieval: ", . true, . - false SQL Active Directory."
  • passwordFormat: " MemberhipPasswordFormat, . Hashed".
    • Hashed: " SHA1. , SHA1, hashAlgorithmType.
    • : " , machineKey Element (ASP.NET Settings Schema).

, SqlMembershipProvider () , SHA1. EncryptPassword/DecryptPasswords, , Encryption/Encoding of passwords ( ).

+4

All Articles