Default password hash

Dag-Erling Smørgrav des at des.no
Mon Jun 11 08:48:16 UTC 2012


Mike Tancsa <mike at sentex.net> writes:
> Actually, any chance of MFC'ing SHA256 and 512 in RELENG_7 ?  Its
> currently not there.

"not there" as in "not supported by crypt(3)"?

> http://phk.freebsd.dk/sagas/md5crypt_eol.html

That blog entry is (partly) why I suggested this change.  I think phk is
being overly pessimistic, but there is no reason not to switch to sha512
when a) it's indubitably stronger and b) that's what the rest of the
world uses.

DES
-- 
Dag-Erling Smørgrav - des at des.no


More information about the freebsd-security mailing list