note 39952 deleted from function.crypt by aidan
| From: | aidan@php.net | Date: | Mon, 05 Jul 2004 10:30:00 +0000 |
| Subject: | note 39952 deleted from function.crypt by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-72599@lists.php.net to get a copy of this message | ||
Note Submitter: cas1650@spam-sucks.nebrwesleyan.edu
----
LDAP stores passwords with a method header in curly brackets before it, so your passwords might look
like this in the database:
{crypt}$1$salt$password
Instead of passing the entire result from LDAP to the crypt() function, crypt() expects the entire
result minus the {crypt} (or {MD5} or whatever) header. So:
$goal = substr($goal, strpos($goal, '$'));
if ($goal == crypt($user_password, $goal)) {
print "Password accepted!";
}
does the right thing.