Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

 
 

Latest commit

 

History

18 Commits

Folders and files

Repository files navigation

GLAuth Argon2-Postgres Plugin

This is a custom GLAuth backend plugin that provides full PostgreSQL support with Argon2id password verification.

It is a drop-in replacement for the official postgres plugin, but overrides the Bind method to use the modern, memory-hard Argon2id algorithm (via github.com/alexedwards/argon2id) instead of the default bcrypt/sha256.

All other features remain 100% identical:

  • Automatic schema creation & migration
  • User/group search
  • includegroups, othergroups, capabilities, etc.
  • Same database schema (uses the passbcrypt column for hashes)

Building the plugin

# Build for your current platform
make plugin

# Build for specific platforms
make plugin_linux_amd64
make plugin_linux_arm64
make plugin_darwin_amd64
make plugin_darwin_arm64

# or
PLUGIN_OS=darwin PLUGIN_ARCH=arm64 make plugin

# Build with build variables
BUILD_VARS="-X main.BuildVersion=1.2.3" make plugin

# Build for all platforms at once
make release

The resulting plugin will be placed in:

bin/<OS>_<ARCH>/argon2-postgres.so

Configuration (glauth.cfg)

[backend]
  datastore     = "plugin"
  plugin        = "/path/to/bin/<OS>_<ARCH>/argon2-postgres.so"
  pluginhandler = "NewPostgresHandler"
  database      = "host=localhost user=glauth password=secret dbname=glauth sslmode=disable"

Note: The pluginhandler line is required and must point to NewPostgresHandler.


Password Storage (Argon2id)

This plugin expects Argon2id hashes in the passbcrypt column of the users table.

Example hash (generated by the argon2id library):

$argon2id$v=19$m=65536,t=3,p=4$abc123...$def456...

You can generate hashes with any library that implements the same parameters (memory=64 MiB, iterations=3, parallelism=4 is the default used by this plugin).

Example one-liner in Go:

hash, _ := argon2id.CreateHash("mysecretpassword", argon2id.DefaultParams)
fmt.Println(hash)

Database Schema

The plugin uses exactly the same schema as the official Postgres backend.

  • Tables: users, ldapgroups, includegroups, capabilities
  • Full schema creation and migration is handled automatically on startup.

For details on seeding the database and the table structure, see the official documentation:

→ https://glauth.github.io/docs/databases.html


Why use this plugin?

  • Modern, secure password hashing (Argon2id is the current winner of the Password Hashing Competition)
  • Full compatibility with existing GLAuth Postgres setups
  • Zero changes to your database schema
  • Easy to maintain (single-file plugin after internalizing basesqlhandler.go)

Just build, drop the .so file in place, update your config, and you’re done.


Made with ❤️ for the GLAuth community
Feel free to open issues or PRs at your fork.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages