Req #62372 [Ver->Wfx]: crypt() and broken backwards compability in SHA rounds
| From: | yohgaki@php.net | Date: | Sat, 19 Jul 2014 02:03:26 +0000 |
| Subject: | Req #62372 [Ver->Wfx]: crypt() and broken backwards compability in SHA rounds | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186739@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62372&edit=1
ID: 62372
Updated by: yohgaki@php.net
Reported by: jani dot ollikainen at mmd dot net
Summary: crypt() and broken backwards compability in SHA
rounds
-Status: Verified
+Status: Wont fix
Type: Feature/Change Request
Package: *Encryption and hash functions
Operating System: *
PHP Version: *
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
This issue will not be addressed.
Users who has obsolete password data should migrate their password data before upgrades. i.e. Update
password hash upon successful login. Ask users to reset password who have not logged in. Developers
can use password_needs_rehash() for this.
This bug is related to https://bugs.php.net/bug.php?id=67653
Previous Comments:
------------------------------------------------------------------------
[2014-07-15 22:47:35] yohgaki@php.net
http://3v4l.org/WJPSl
HASH:
$6$rounds=10$qNElXs2yMnL2.GNS3kiM7DqmGbFLdQfIwu2691aJgT3xgJazPLtw7RPKz3Dp8RIc4b5fmJ7qvlq/mPN8a.rE40
- CRYPT:
$6$rounds=1000$qNElXs2yMnL2.GNS$/q7trYkbKkoJernsumbObt2IysdXGRx/ytFaG0HBC97rHHhYRQvUcyEuRHP6h5yj8V.fH7XKEw5hjofVmYONw1
NO MATCH
rounds became 10 to 1000.
------------------------------------------------------------------------
[2013-02-26 08:23:20] m dot staab at complex-it dot de
I have the very same issues. Updating from PHP5.2.4 to PHP5.4.11 and now my passwords which were
hased using PHP5.2.4 do not match any longer on PHP5.4.11.
I found no way how to re-produce passwords on PHP5.4.11 like they were generated on PHP5.2.4 and
therefore I have no way to upgrade users which already have a password to a newly generated with
PHP5.4.11..
The only way I can think of is a password-reset for all of our users?!
------------------------------------------------------------------------
[2012-06-20 20:33:17] jani dot ollikainen at mmd dot net
Oh now I get what I did wrong with PHP 5.1.6. It doesn't understand rounds at
all, it's just looks like it does, but it uses it as salt and new PHP doesn't
allow = in salt, so it doesn't work as they see different salt in it. So the
compatibility issue is with salt string, not in rounds at all.
This can be work around in PHP 5.1.6 not to use salt's which newer versions
don't understand, but if you already use them, then you're in big trouble.
Another one is that if I have password like: http://3v4l.org/amNND
The hash is generated with patched PHP 5.4.4 with ROUNDS_MIN 1, but it could be
from some other system. PHP cannot verify it, as the rounds limit 1000 is
enforced. To me enforcing it seems to limit compability.
------------------------------------------------------------------------
[2012-06-20 19:32:11] arjen at react dot com
Looks like PHP <= 5.1.7 has a limit on the saltstring of 9 chars.
If no $rounds is specified AND a salstring of 9 chars, all versions return the
same hash: http://3v4l.org/nDiFd (2nd line, 1st line is with
long hash).
------------------------------------------------------------------------
[2012-06-20 11:44:29] jani dot ollikainen at mmd dot net
Tested with patched 5.4.4 where:
#define ROUNDS_MIN 1
HASH:
$6$rounds=10$qNElXs2yMnL2.GNS3kiM7DqmGbFLdQfIwu2691aJgT3xgJazPLtw7RPKz3Dp8RIc4b5fmJ7qvlq/mPN8a.rE40
- CRYPT:
$6$rounds=10$qNElXs2yMnL2.GNS$YwaYQmhwsN2RzBImxlEjIL.0/YLlfYCDmyfozkCQWNKdKgZQtTpK3Y/TAw31deCnJrDzgrqpI6ckvJCBsoeNB/
NO MATCH
So problem isn't only in ROUNDS_MIN. Also I know that my hash hasn't $ after salt, but
that's how PHP 5.1.6 creates it. Tested also with adding $ and result is similar:
HASH:
$6$rounds=10$qNElXs2yMnL2.GNS$3kiM7DqmGbFLdQfIwu2691aJgT3xgJazPLtw7RPKz3Dp8RIc4b5fmJ7qvlq/mPN8a.rE40
- CRYPT:
$6$rounds=10$qNElXs2yMnL2.GNS$YwaYQmhwsN2RzBImxlEjIL.0/YLlfYCDmyfozkCQWNKdKgZQtTpK3Y/TAw31deCnJrDzgrqpI6ckvJCBsoeNB/
NO MATCH
So something else is also different...
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62372
--
Edit this bug report at https://bugs.php.net/bug.php?id=62372&edit=1