Re: PEAR Auth, File_Passwd, and crypt() limitation?
| From: | Paul M Jones | Date: | Wed, 13 Apr 2005 23:14:43 +0000 |
| Subject: | Re: PEAR Auth, File_Passwd, and crypt() limitation? | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-37226@lists.php.net to get a copy of this message | ||
Paul M Jones wrote:
And the results are negative. The Apache-generated MD5 for a given string (which I will not give here ;-) is this ...Modern versions of htpasswd use by default SHA a much serious algo than DES or MD5. Well, it seems that a chineese team have found some collitions in the SHA hashing algo, what could compromise it too.Hm. My Apache install is the OpenBSD 3.5 version, and it seems to be using the DES scheme. A little Googling ... aha:http://httpd.apache.org/docs/programs/htpasswd.htmlDES is the default. The -m switch for MD5 is available, but is not supported on Windows. However, the docs state that "The MD5 algorithm used by htpasswd is specific to the Apache software; passwords encrypted using it will not be usable with other Web servers." I wonder if this applies to trying to use the PHP MD5 function as well. I guess I can see some experimentation in my future.
$apr1$c6lOG...$wfdl2Kf13kRmfOfVQ.VPj1... but the PHP MD5 function gives this:
7cbb3252ba6b7e9c422fac5334d22054So I don't think the Apache-provided Apache-specific MD5 function will be a good replacement, although I would be happy to be proved wrong. Maybe SHA will do it. Other ideas? -- pmj