As of 2014-07-29, this is a tool for developers only. You need to write code for the external system to access the information. See developer documentation at User Encryption. The system is designed so that encryption can later be implemented for data in Tiki (files, tracker items, etc.)
User encryption aims to a provide secure, personal storage of sensitive data, e.g. external usernames and passwords.
Table of contents
User Encryption enables secure storage of such external log-in credentials. The decryption key is not stored by Tiki, and it is only available when the user is logged in.
- This is a new an experimental feature in Tiki 13 and has been backported for Tiki 12.2, so it is available (as experimental) in the LTS version
- Use the Domain Password module to allow the user to specify username and password
- CryptLib must be integrated by coding to access the domain. CryptLib provides the decrypted domain credentials
See also User Encryption.
The interface to a linked system, uses the password domain name to look-up a user's credentials for the system.
The module "Domain Password", prompts the user for a password.
The password is encrypted and saved associated with the domain specified in the module.
Make sure OpenSSL (Tiki18+) / Mcrypt (Tiki pre-18) is available
Before you enable "User Encryption", make sure that the OpenSSL (Tiki18+) / Mcrypt (Tiki pre-18) PHP extension is available. It is required to encrypt the passwords securely.
The names of the password domains must be unique.
By default the currently logged in Tiki username will be used. By setting "Use current user" = "n", the user must also specify a username.
The view mode is displayed initially. The user can choose to edit the credentials, if the module configuration allows it.
If the password domain is misconfigured, an error message is displayed.
If the user click edit, the credentials can be edited.
If the current Tiki user is being used, only the password can be edited.
User Encryption @ dev.tiki.org