Hello
We are currently evaluating Crowd on Linux with postgresql back-end. We would like to use it to authenticate/authorise users of Jira, Confluence,Stash and the Calendar - as well as some of our own web-based systems. We would like to know how you secure the passwords in the code and DB. For instance:
How do you mitigate against a man-in-the middle attack?
Could someone obtain the passwords if they had access to the crowd DB?
Any further info regarding security would be useful. Apologies if this has been covered elsewhere.