Bug #10822 Updated: CRYPT_SALT_LENGTH == 2 even when CRYPT_MD5 available
| From: | sniper@php.net | Date: | Sat, 04 Aug 2001 23:54:59 +0000 |
| Subject: | Bug #10822 Updated: CRYPT_SALT_LENGTH == 2 even when CRYPT_MD5 available | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-62113@lists.php.net to get a copy of this message | ||
ID: 10822
Updated by: sniper
Reported By: jo@feuersee.de
Old Status: Open
Status: Closed
Bug Type: *Encryption and hash functions
Operating System: Linux 2.4.4
PHP Version: 4.0.5
New Comment:
Fixed in CVS.
--Jani
Previous Comments:
------------------------------------------------------------------------
[2001-05-11 18:54:00] jo@feuersee.de
Against the documentation, at least on Linux systems the const CRYPT_SALT_LENGTH is 2 even when the
system is capable of encrypting MD5.
Most likely, this is related to bug #9177.
As stated there, I compiled php (after a make clean; rm config.cache) without openssl support, but
<?php
printf("%d", CRYPT_SALT_LENGTH);
?>
still emits 2 (but MD5 encryption works fine).
It gets pretty complicated to maintain compatibility with former versions of PHP. This bug also
causes compatibility probs when porting DBs with crypt() encrypted passwords from Linux to BSD and
vice versa (MD5 ist std on most (all?) BSD platforms.
I'd like to propose the following:
CRYPT_SALT_LENGTH should be set to the longest salt the system is capable of (like it is staded in
the docs).
The 4 different consts specifying the salt of a requested encryprion (eg. CRYPT_MD5) should be set
to 0 (==not available) or the salt length for this kind/flavour of encryption.
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=10822&edit=1