Re: Auth feature

From: Date: Sun, 06 Apr 2003 08:32:58 +0000
Subject: Re: Auth feature
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-14936@lists.php.net to get a copy of this message
Hi, Alan Knowles schrieb:
The algorithm sound good -except I would assume the md5 would be of username:{encrypted password}:challenge as most normal password storage mechanisms store passwords encrypted by default. - so you would not be able to get the cleartext password.. I think both should possible, md5(id + challenge + md5(pass)) wich isn't RFC conform and md5(ip + challenge + pass).
I strongly recommend implementing also RFC 1994 conform CHAP, because otherwise the RADIUS Auth Container doesen't work. bye, -- ------------------------------- ------------------------------------- Michael Bretterklieber - Michael.Bretterklieber@jawa.at JAWA Management Software GmbH - http://www.jawa.at Liebenauer Hauptstr. 200 -------------- privat --------------- A-8041 GRAZ GSM: ++43-(0)676-93 96 698 Tel: ++43-(0)316-403274-12 E-mail: michael@bretterklieber.com Fax: ++43-(0)316-403274-10 http://www.bretterklieber.com ------------------------------- ------------------------------------- "...the number of UNIX installations has grown to 10, with more expected..." - Dennis Ritchie and Ken Thompson, June 1972

« previous php.pear.dev (#14936) next »