PHP 4.0 Bug #5821 Updated: crypt() with blowfish fails
| From: | Bug Database | Date: | Fri, 28 Jul 2000 04:15:26 +0000 |
| Subject: | PHP 4.0 Bug #5821 Updated: crypt() with blowfish fails | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-26654@lists.php.net to get a copy of this message | ||
ID: 5821
User Update by: cjc5@po.cwru.edu
Status: Open
Bug Type: Scripting Engine problem
Description: crypt() with blowfish fails
The obvious fix is to change the salt length for blowfish passwords from 17 characters to 60. When
I put this change into the latest cvs php it now works as expected.
Interestingly it seems that if the salt is less than 60 characters then previous stuff in memory
gets used. Thus with the fix the test program gives the correct encryption for both the full salt
and if I use substr to pull out only 7 characters. I don't know if this is a php or OpenBSD
problem.
Full Bug description available at: http://bugs.php.net/?id=5821