i386/52392: Password lengths over 8 chracters are ignored

Chris Lewis chris at digitalwaffle.net
Sun May 18 04:30:12 PDT 2003


The following reply was made to PR i386/52392; it has been noted by GNATS.

From: Chris Lewis <chris at digitalwaffle.net>
To: freebsd-gnats-submit at FreeBSD.org
Cc:  
Subject: Re: i386/52392: Password lengths over 8 chracters are ignored
Date: Sun, 18 May 2003 12:26:59 +0100

 At 11:57 18/05/2003, Simon L. Nielsen wrote:
 >I think the problem is that adduser uses DES passwords by default even
 >when you have set MD5 e.g. in login.conf.  This has been discussed a few
 >times before, but I can't remember the reason for this.  Try searching
 >the mailling list archives.
 
 Agreed - /usr/sbin/adduser calls the Perl function crypt() which is simply 
 DES... d'oh.
 
 Might as well considered this bug closed.
 
 Regards,
 
 --
 Chris Lewis [boff]
 
 Encryption is mathematical warfare.
 Mathematics is the universal language.
 Encryption is secrecy.
 Secrecy is a declaration of war.
 


More information about the freebsd-i386 mailing list