Re: Shadow Passwords
| From: | Paul Meagher | Date: | Sun, 16 Dec 2001 21:40:11 +0000 |
| Subject: | Re: Shadow Passwords | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-3499@lists.php.net to get a copy of this message | ||
> > To invoke MD5 from the crypt function you need to give it a 12
character
> > salt instead of a 2 character salt.
> >
> > Just change this:
> >
> > crypt($pass,substr($this->users[$user],0,2))
> >
> > To this:
> >
> > crypt($pass,substr($this->users[$user],0,12))
>
> to the best of my knowledge, you can always just pass the full crypted
> password in as the salt. the underlying crypt() implementation will just
> use the relevant bits by itself.
>
> jim
I believe this is what you are suggesting (don't hand in a salt of a
particular length but just hand in the full crypted password). :
crypt($pass, $this->users[$user] )
Where $pass is the user supplied password and $this->users[$users] is the
crypted password that appears in the shadow file.
The output of crypt does in fact generate a password that matches the one
that appears in the shadow password file.
This suggests that to increase the generality of the File_Passwd class you
should eliminate the constraint of having a salt of a particular length?
Regards,
Paul Meagher
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, e-mail: pear-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: pear-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>