Date: Mon, 30 Sep 2013 14:16:11 -0400 From: "A.J. Kehoe IV (Nanoman)" <nanoman@nanoman.ca> To: FreeBSD-current@FreeBSD.org Subject: Better Password Hashes Message-ID: <20130930181611.GA90404@nanocomputer.nanoman.ca>
next in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] On the FreeBSD-security mailing list earlier this year, I brought up the issue of improving password hashes. The patches I included were for FreeBSD 9-STABLE, which is what I use primarily. gjb@ kindly advised me that the patches would need to be extensively tested on CURRENT before they'd be merged into 9-STABLE. Derek Marcotte, who wrote the patches, sent me his updated versions for CURRENT, and I've submitted these in a PR: http://www.freebsd.org/cgi/query-pr.cgi?pr=182518 (My apologies for neglecting to prefix the PR's Subject line with "[patch]".) I've been using Derek's patches on my own production systems for the past few months, and I'm happy to say that they're working perfectly. So, what we need now is to have these audited and tested by a larger audience, and then merged into 9-STABLE when a sufficient number of people are satisfied. Let the testing begin! -- A.J. Kehoe IV (Nanoman) | /"\ ASCII Ribbon Campaign Nanoman's Company | \ / - No HTML/RTF in E-mail E-mail: nanoman@nanoman.ca | X - No proprietary attachments WWW: http://www.nanoman.ca/ | / \ - Respect for open standards [-- Attachment #2 --] 0P *H A0=10 + 0 *H 0w0_ [0 *H 0y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org0 130906235134Z 140305235134Z0=10UCAcert WoT User1!0 *H nanoman@nanoman.ca0"0 *H 0 VDj @[H}K4٪:CJyckXmi ~F6x1JoeHQL`w&.PH"w}|oѬݘ2r6ڛ? p .yaw Nc^ʽhNmHo$lsB1hXy XUşkք))RnZg_Îhc$u^SϏdmoA#k>x;As B0>0U0 0V `HB IGTo get your own certificate for FREE head over to http://www.CAcert.org0U0@U%907++ +7 +7 `HB02+&0$0"+0http://ocsp.cacert.org01U*0(0&$" http://crl.cacert.org/revoke.crl0U0nanoman@nanoman.ca0 *H HO7췣=F*Mk-r |#,s0y99oZ,q~YI}s.P!_Nǘl[Һ*u4{q\cj!RtjO_ڦrʳ)fjh)c@7BtK/]*JԁǞ8ݸ{Pu[~71\йw;\\M0fvm}`]9vgA6+1l}aAo u*у\gJ%=OF7M!i?@DG|pM,B0JC|u=a6;y?$H&Mj7+h4@Pi@2+[J/$3ObxC;.(v9+7[[JNdVJ8N`^ʛDɲi_٭ىeRkCS ^s_63o'$~D$d{}>z;M0=0% 0 *H 0y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org0 030330122949Z 330329122949Z0y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org0"0 *H 0 "F}6(P3@K;f?1k6|Nw6A Fs`n~XdͰEcg ҿ>L5]l!ޞ ٺf27rXɎ^> l[df*zKSy{/ a+~MVڒDAX`efD˔B~ehQWkzr%[ 2H.0B%k?:SHҶ4zX+[8]fɘמtqr`o34v>$zoE8GAJ. Yתғ}h.KX/ꕧTۋQ"þ,x ӊ/?Qe!eE|ALO)!3uQwi" Ṕ1{8h[+~_rLK Wʑ u!7c g>FOp gYͺbA )d)B"xC QKZZqs 00U2Ұ:90U#02Ұ:9ѡ}{0y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org 0U002U+0)0'%#!https://www.cacert.org/revoke.crl00 `HB#!https://www.cacert.org/revoke.crl04 `HB'%http://www.cacert.org/index.php?id=100V `HB IGTo get your own certificate for FREE head over to http://www.cacert.org0 *H (\5 ojhX>ÐZ`CpbgX 06;Htq>+h4b@F;S(fSM];`yi;eƁ\MU7paj|.T>O!܂EMs<evj7$NmQďʖmC0e';{CCcCh"{Z>7;N˛͚۲p-JذoEH3<2*T#Gdzqc~/ܟ+H%B>Wiw4 Kʠƌ27hs_QIS6 Ly:u pg/y=sog/${H5)@`ᖆPzY؏!ς;kV#lH<N/ So.t:c¦D l$pG.Բ d$ܡ5ԼU.}UZ֓v%sLC1\0X00y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org [0 + 0 *H 1 *H 0 *H 1 130930181611Z0# *H 1Kg䅲e o0R *H 1E0C0 *H 0*H 0 *H @0+0 *H (0 *H uZ@y_;ǓT{,~35_8v&-⡬FSgMP"(/)toY %pa SWj\c Ǜq9z;PH*BuԁŊB}dD;HBDɬA F@[5O_a=^RuN_,SY){lU%&`]er03Krb1
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20130930181611.GA90404>
