From 75b77a2b2643316fed1e1e510f607809be2dc813 Mon Sep 17 00:00:00 2001 From: Adolf Belka Date: Wed, 7 May 2025 11:58:33 +0200 Subject: [PATCH] passwords.c: Update number of rounds for passwords from 7 to 10 - This improves the security of the root and admin passwords created and makes it the same as used for the proxy local auth password code in proxy.cgi & chpasswd.cgi Signed-off-by: Adolf Belka Signed-off-by: Michael Tremer --- src/setup/passwords.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/setup/passwords.c b/src/setup/passwords.c index 6242577af9..bb6ffe8e68 100644 --- a/src/setup/passwords.c +++ b/src/setup/passwords.c @@ -56,7 +56,7 @@ int handleadminpassword(void) return 0; snprintf(commandstring, STRING_SIZE, - "/usr/bin/htpasswd -c -B -C 7 -b " CONFIG_ROOT "/auth/users admin '%s'", password); + "/usr/bin/htpasswd -c -B -C 10 -b " CONFIG_ROOT "/auth/users admin '%s'", password); sprintf(message, _("Setting %s 'admin' user password..."), NAME); if (runhiddencommandwithstatus(commandstring, _("Setting password"), message, NULL)) { sprintf(message, _("Problem setting %s 'admin' user password."), NAME); -- 2.39.5