]> git.ipfire.org Git - people/dweismueller/ipfire-2.x.git/commit
Revert "setup: Store passwords in SHA format"
authorMichael Tremer <michael.tremer@ipfire.org>
Sat, 15 Oct 2016 21:38:01 +0000 (22:38 +0100)
committerMichael Tremer <michael.tremer@ipfire.org>
Sat, 15 Oct 2016 21:38:01 +0000 (22:38 +0100)
commit96473f525dcec4115b9bab0b305ff5b92194b134
tree18460ba9a2897e8ea11dd17dafb5b98a3478a5b9
parent6920fbe86df2cacefc1a91b9590d84a495734e65
Revert "setup: Store passwords in SHA format"

This reverts commit eef9b2529c3cab522dac4f4bcfa1a0075376514e.

It appears that htpasswd is not salting any passwords that are
stored with the SHA (-s) algorithm. MD5 passwords however are
salted.

That leads us to the conclusion that the "MD5 algorithm" in htpasswd
is more secure than the "SHA algorithm" although the hash function
itself should be stronger.

With a rainbow table, cracking "SHA" is easily done.

A rainbow table for "MD5" + salt would be way too large to be
efficiently stored.

Hence this commit is reverted to old behaviour to avoid the clear
failure of design in SHA.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org>
config/rootfiles/core/106/filelists/files
src/setup/passwords.c