note 20300 deleted from function.crypt by aidan
| From: | aidan@php.net | Date: | Mon, 05 Jul 2004 10:25:03 +0000 |
| Subject: | note 20300 deleted from function.crypt by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-72572@lists.php.net to get a copy of this message | ||
Note Submitter: ian_n@
----
Regarding the comments above by icecube@fr.fm:
It is *NOT* necessary (in my experience) to use the first two characters of your password as the
salt in order to generate .htaccess-based authentication with DES (and in fact it seems rather silly
to prefix a plain-text portion of the password to the encrypted value). At least that is what
I've found in my experiments under Linux/Apache.
If you're doing any matching yourself, just make sure you crypt() the match string using the
same salt as the encrypted string.