Re: [PROPOSED] password_hash RFC - Implementing simplified password hashing functions
| From: | Stas Malyshev | Date: | Thu, 12 Jul 2012 18:32:17 +0000 |
| Subject: | Re: [PROPOSED] password_hash RFC - Implementing simplified password hashing functions | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-61186@lists.php.net to get a copy of this message | ||
Hi!
> https://wiki.php.net/rfc/password_hash
Looks good. The only question I have is for password_make_salt() - do we
need the user to specify length? I think length is defined by the
algorithm in the most cases. Maybe convert it to password_make_salt(int
$salt_type = PASSWORD_SALT_BCRYPT, int $length)
with both arguments optional and one of salt types being
PASSWORD_SALT_OTHER which just generates given length?
--
Stanislav Malyshev, Software Architect
SugarCRM: http://www.sugarcrm.com/
(408)454-6900 ext. 227