Re: Shadow Passwords

From: Date: Sun, 16 Dec 2001 21:40:11 +0000
Subject: Re: Shadow Passwords
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-3499@lists.php.net to get a copy of this message
> > To invoke MD5 from the crypt function you need to give it a 12 character > > salt instead of a 2 character salt. > > > > Just change this: > > > > crypt($pass,substr($this->users[$user],0,2)) > > > > To this: > > > > crypt($pass,substr($this->users[$user],0,12)) > > to the best of my knowledge, you can always just pass the full crypted > password in as the salt. the underlying crypt() implementation will just > use the relevant bits by itself. > > jim I believe this is what you are suggesting (don't hand in a salt of a particular length but just hand in the full crypted password). : crypt($pass, $this->users[$user] ) Where $pass is the user supplied password and $this->users[$users] is the crypted password that appears in the shadow file. The output of crypt does in fact generate a password that matches the one that appears in the shadow password file. This suggests that to increase the generality of the File_Passwd class you should eliminate the constraint of having a salt of a particular length? Regards, Paul Meagher > -- > PEAR Development Mailing List (http://pear.php.net/) > To unsubscribe, e-mail: pear-dev-unsubscribe@lists.php.net > For additional commands, e-mail: pear-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.pear.dev (#3499) next »