Shadow Passwords
| From: | Paul Meagher | Date: | Sat, 15 Dec 2001 18:19:56 +0000 |
| Subject: | Shadow Passwords | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-3494@lists.php.net to get a copy of this message | ||
I was attempting to use the File_Passwd class developed by Rasmus to
authenticate against a shadow password file.
It doesn't appear to work. The password I read from the file and the
encrypted version of the user supplied password are different suggesting
that shadow password files might use a different encryption function? Or
maybe I'm doing something wrong here...
The shadow password read from the file:
$1$0pZjv6IT$lfRwC6m5vMU8XGLkfrU.v/
The encrypted password generated using the user supplied password and this
function - crypt($pass,substr($this->users[$user],0,2));
$1$$zXMQxpKDH91klGV8Q0Jnn
I needed to change the permissions on the shadow password file (world
readable) to access it using a web based php script. I was just doing this
to test the class to see if it could actually authenticate against a shadow
file. I am testing this on a Slackware Linux 8.0 platform.
As an aside, is there any way to have a web based php script access the
shadow file in a way that is more secure than having to change the
permissions on the shadow file to world readable?
Regards,
Paul Meagher