Date: Fri, 7 Mar 2014 16:52:23 -0500 From: "A.J. Kehoe IV (Nanoman)" <nanoman@nanoman.ca> To: Allan Jude <freebsd@allanjude.com>, secteam@FreeBSD.org Cc: freebsd-current@freebsd.org Subject: Re: Feature Proposal: Transparent upgrade of crypt() algorithms Message-ID: <20140307215223.GB49137@nanocomputer.nanoman.ca> In-Reply-To: <531A2CC1.8080802@allanjude.com> References: <2167732.JmQmEPMV2N@desktop.reztek> <201403070913.30359.jhb@freebsd.org> <5319DE84.3040602@allanjude.com> <20140307161313.GA49137@nanocomputer.nanoman.ca> <531A2CC1.8080802@allanjude.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Allan Jude wrote: >On 2014-03-07 11:13, A.J. Kehoe IV (Nanoman) wrote: >> Allan Jude wrote: >> >> [...] >> >>> Honestly, my use case is just silently upgrading the strength of the >>> hashing algorithm (when combined with my other feature request). >>> Updating my bcrypt hashes from $2a$04$ to $2b$12$ or something. Same >>> applies for the default sha512, maybe I want to update to rounds=15000 >> >> Like this? >> >> http://www.freebsd.org/cgi/query-pr.cgi?pr=182518 >> >> Request for comments: >> >> http://docs.freebsd.org/cgi/mid.cgi?20140106205156.GD4903 >> > >This looks like what we wanted. In the feedback you talked about some >changes to your patch required to make it work, is there any progress on >those? Derek's patches worked perfectly for our needs, but we're the sort of people who use vipw and our own utilities for user management. It wasn't until later that we discovered at least one other file would need patching to satisfy everyone. We didn't want to employ the same copy-pasta method, so we asked for feedback about our proposed alternative. secteam@, do you have any comments? Before we put any more work into this, we want to be sure that our proposal is an acceptable one. -- A.J. Kehoe IV (Nanoman) | /"\ ASCII Ribbon Campaign Nanoman's Company | \ / - No HTML/RTF in E-mail E-mail: nanoman@nanoman.ca | X - No proprietary attachments WWW: http://www.nanoman.ca/ | / \ - Respect for open standards [-- Attachment #2 --] 0P *H A0=10 + 0 *H 0w0_0 *H 0y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org0 140224170909Z 140823170909Z0=10UCAcert WoT User1!0 *H nanoman@nanoman.ca0"0 *H 0 VDj @[H}K4٪:CJyckXmi ~F6x1JoeHQL`w&.PH"w}|oѬݘ2r6ڛ? p .yaw Nc^ʽhNmHo$lsB1hXy XUşkք))RnZg_Îhc$u^SϏdmoA#k>x;As B0>0U0 0V `HB IGTo get your own certificate for FREE head over to http://www.CAcert.org0U0@U%907++ +7 +7 `HB02+&0$0"+0http://ocsp.cacert.org01U*0(0&$" http://crl.cacert.org/revoke.crl0U0nanoman@nanoman.ca0 *H h\MDm5K8brO/;>1Sl(,M~P*SC@6,~̞C(hܫcINN&gG͖1+L=)Vj7$`Jr7w!2G.bF컘0!7sΠqSI[)8kFtyI&֛$S]SDKQI=OvSXҫYJ.Ms&>.ߋFU#<1ɭe4B^KQ@wj*y =3D1^|NS63𠢬DseҐ#7E3WRL{+I~}崋 Jj.BNm{mtMлP7 .|M'q*fkaՊ d @,Ud,E@q(GED;J:hN^S$pXWR]r%H0=0% 0 *H 0y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org0 030330122949Z 330329122949Z0y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org0"0 *H 0 "F}6(P3@K;f?1k6|Nw6A Fs`n~XdͰEcg ҿ>L5]l!ޞ ٺf27rXɎ^> l[df*zKSy{/ a+~MVڒDAX`efD˔B~ehQWkzr%[ 2H.0B%k?:SHҶ4zX+[8]fɘמtqr`o34v>$zoE8GAJ. Yתғ}h.KX/ꕧTۋQ"þ,x ӊ/?Qe!eE|ALO)!3uQwi" Ṕ1{8h[+~_rLK Wʑ u!7c g>FOp gYͺbA )d)B"xC QKZZqs 00U2Ұ:90U#02Ұ:9ѡ}{0y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org 0U002U+0)0'%#!https://www.cacert.org/revoke.crl00 `HB#!https://www.cacert.org/revoke.crl04 `HB'%http://www.cacert.org/index.php?id=100V `HB IGTo get your own certificate for FREE head over to http://www.cacert.org0 *H (\5 ojhX>ÐZ`CpbgX 06;Htq>+h4b@F;S(fSM];`yi;eƁ\MU7paj|.T>O!܂EMs<evj7$NmQďʖmC0e';{CCcCh"{Z>7;N˛͚۲p-JذoEH3<2*T#Gdzqc~/ܟ+H%B>Wiw4 Kʠƌ27hs_QIS6 Ly:u pg/y=sog/${H5)@`ᖆPzY؏!ς;kV#lH<N/ So.t:c¦D l$pG.Բ d$ܡ5ԼU.}UZ֓v%sLC1\0X00y10U Root CA10Uhttp://www.cacert.org1"0 UCA Cert Signing Authority1!0 *H support@cacert.org0 + 0 *H 1 *H 0 *H 1 140307215223Z0# *H 1hÁc0O&>q%0R *H 1E0C0 *H 0*H 0 *H @0+0 *H (0 *H Xz.$nPNKÄPBjJ XяID4U"oguJt!%Ip*_rԳ_)2CcAVb`YJݟVGUG_98xpeaxUIdb+lG ÅvzԚK>1) P-[q#3X!S H.1$e6ew[ ƗXa3aO0lQVDߣhv
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20140307215223.GB49137>
