Re: PEAR Auth, File_Passwd, and crypt() limitation?

From: Date: Wed, 13 Apr 2005 22:52:16 +0000
Subject: Re: PEAR Auth, File_Passwd, and crypt() limitation?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37223@lists.php.net to get a copy of this message
Tomas V.V.Cox wrote:
As shown in the comments for php crypt(), if you don't supply a salt that limitation is not true.
True, but File_Passwd does in fact provide the salt. Thus, the 8 char limit applies. This may be a security issue; just wanted to point it out and see if I was far off base or near home.
Modern versions of htpasswd use by default SHA a much serious algo than DES or MD5. Well, it seems that a chineese team have found some collitions in the SHA hashing algo, what could compromise it too.
Hm. My Apache install is the OpenBSD 3.5 version, and it seems to be using the DES scheme. A little Googling ... aha:
    http://httpd.apache.org/docs/programs/htpasswd.html
DES is the default. The -m switch for MD5 is available, but is not supported on Windows. However, the docs state that "The MD5 algorithm used by htpasswd is specific to the Apache software; passwords encrypted using it will not be usable with other Web servers." I wonder if this applies to trying to use the PHP MD5 function as well. I guess I can see some experimentation in my future. -- pmj

« previous php.pear.dev (#37223) next »