note 71748 deleted from function.crypt by joey
| From: | joey@php.net | Date: | Sat, 19 May 2012 20:40:44 +0000 |
| Subject: | note 71748 deleted from function.crypt by joey | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-188083@lists.php.net to get a copy of this message | ||
Note Submitter: tserong at sgi dot com
----
Blowfish doesn't use a sixteen character salt, it uses sixteen *bytes* of salt. So (courtesy
of the docs for the Crypt::Eksblowfish::Bcrypt Perl module), it's:
"$2", optional "a", "$", two digits, "$", and 22 base 64
digits
If the salt is not long enough, crypt will return "*0" and you will have no idea what is
wrong. Interestingly, the example in the documentation with a trailing '$' in the salt
does not work. Replace the '$' with a '.', and the output appears as
advertised.