Bug #15769 Updated: php-4.0 crypt("abc") != php-4.1 crypt("abc")

From: Date: Thu, 28 Feb 2002 14:55:59 +0000
Subject: Bug #15769 Updated: php-4.0 crypt("abc") != php-4.1 crypt("abc")
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-1293@lists.php.net to get a copy of this message
ID: 15769 Updated by: edink@php.net -Summary: php-4.0 crypt("abc") != php-4.1 crypt("abc") Reported By: php@8304.ch Status: Bogus Bug Type: *Encryption and hash functions Operating System: linux PHP Version: 4.1.1 New Comment: The behaviour unfortunatelly did change (and its not documented). You don't have to disable MD5 like that to get regular crypt, but you would need to generate a two character salt, which would then be passed as a second argument to crypt(). Previous Comments: ------------------------------------------------------------------------ [2002-02-28 07:32:22] php@8304.ch ok, found a solution : 1. ./configure [options] 2. edit main/php_config.h and set PHP_MD5_CRYPT = 0 3. compile. ------------------------------------------------------------------------ [2002-02-28 05:44:41] php@8304.ch from the docs: > If no salt is provided, PHP will auto-generate a standard > 2 character salt by default, unless the default encryption > type on the system is MD5, in which case a random > MD5-compatible salt is generated. well, the "default encryption type" on the system has not changed between upgrade from 4.0 to 4.1, so why does the crypt behaviour change on the way? I really see that as a bug, or please tell me how to revert to the "normal" crypt (DES). Saw no options in the ./configure as well... :/ ------------------------------------------------------------------------ [2002-02-28 02:09:06] sniper@php.net This is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php http://www.php.net/manual/en/function.crypt.php ------------------------------------------------------------------------ [2002-02-28 02:08:38] sniper@php.net This is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php ------------------------------------------------------------------------ [2002-02-27 19:53:56] php@8304.ch On the same system after upgrade, the result of crypt with only one arguments has another format: before (php 4.0.6) it was the standard 13 chars string, and now this md5-like hash is comming: "$1$ngOfu9A.$AoUUzzXjwxQiqKq7c2wDt1"... Shouldn't the default behaviour of crypt() stay the same on a specific system ? This way it breaks a lots of customers scripts on the web server on upgrade, and this is *very* annoying. (no, I can't tell all people: rewrite all your scripts and use 2 args with the crypt command). Isn't there a way to tell at compliation time: crypt() defaults to DES? Regards, Olivier ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=15769&edit=1

« previous php.bugs (#1293) next »