#19764 [Opn->Fbk]: crypt() only generates DES results, not md5, when compiled --with-apxs2
| From: | iliaa@php.net | Date: | Sat, 05 Oct 2002 06:27:40 +0000 |
| Subject: | #19764 [Opn->Fbk]: crypt() only generates DES results, not md5, when compiled --with-apxs2 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-21538@lists.php.net to get a copy of this message | ||
ID: 19764
Updated by: iliaa@php.net
Reported By: php@onethumb.com
-Status: Open
+Status: Feedback
Bug Type: *Encryption and hash functions
Operating System: Redhat 7.3, kernel 2.4.19
PHP Version: 4.2.3
New Comment:
Seems to work just fine here for me on Linux. Could you show me what
salt are you using (value of the $testsalt variable) as well as the
results that you get.
Previous Comments:
------------------------------------------------------------------------
[2002-10-04 21:28:05] php@onethumb.com
Looks like it is an OpenSSL problem, afterall.
When I compile Apache 2.0.43 without SSL, PHP's crypt() behaves
properly.
Sorry for the bug entry. I guess I'll go bother the OpenSSL guys.
------------------------------------------------------------------------
[2002-10-04 19:36:02] php@onethumb.com
I should note, also, that the following constants are the correct
values, too:
CRYPT_MD5 = 1
CRYPT_SALT_LENGTH = 12.
I just tried the latest CVS snapshot of 4.3.0-dev (200210040900) and I
have the same problem there. If I configure with '--with-apxs2' I get
DES results, and if I build with '--without-apache' the standalone php
binary works fine.
I even went as far as to force configure to turn DES off, and indeed,
after compiling, CRYPT_STD_DES = 0. Nevertheless, crypt() returned DES
results.
I will try whatever CVS snapshot of Apache2 I can get my hands on, but
this appears on the surface to be a php bug.
------------------------------------------------------------------------
[2002-10-04 19:21:24] php@onethumb.com
I haven't tried the CVS snapshots yet, though I will shortly. I did go
back and try php4.2.2, and the problem seems to exist there as well.
Basically, when I compile PHP standalone, or for apxs, the crypt()
function correctly returns MD5 results when it should, but when
compiled with apxs2, it does not. Instead, it generates DES results,
regardless of what salt is given, or even if no salt is provided.
I've also tried it both with and without "--with-openssl". It makes no
difference.
This is with Apache 2.0.42.
Script used:
<? echo crypt("test", '$1$testsalt'); ?>
Works (does MD5 correctly):
'./configure' '--enable-exif' '--with-gd'
'--enable-gd-native-ttf'
'--with-jpeg-dir=/usr' '--with-png-dir=/usr'
'--with-freetype-dir=/usr'
'--with-ttf' '--with-mysql=/usr' '--with-zlib'
'--enable-inline-optimization' '--with-bz2' '--with-openssl'
Does not (only returns DES):
'./configure' '--enable-exif' '--with-gd'
'--enable-gd-native-ttf'
'--with-jpeg-dir=/usr' '--with-png-dir=/usr'
'--with-freetype-dir=/usr'
'--with-ttf' '--with-apxs2' '--with-mysql=/usr'
'--with-zlib'
'--enable-inline-optimization' '--with-bz2' '--with-openssl'
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=19764&edit=1