md5 salt

markm at freebsd.org markm at freebsd.org
Tue Sep 16 00:05:17 PDT 2003


Peter Pentchev writes:
> The crypt.c and crypt-md5.c files in src/lib/libcrypt/ do not really
> pose any restrictions on the salt, short of the obvious one of its
> not containing a '$' character :)
> 
> I guess going with the base64 characters would be a good bet.

Any character that does not mess up master.passwd. So ":" is also a no-no.

M
--
Mark Murray
iumop ap!sdn w,I idlaH


More information about the freebsd-security mailing list