From owner-freebsd-security@FreeBSD.ORG Mon Jun 11 09:47:19 2012 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 2D55F1065670; Mon, 11 Jun 2012 09:47:19 +0000 (UTC) (envelope-from des@des.no) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id DAECD8FC1D; Mon, 11 Jun 2012 09:47:18 +0000 (UTC) Received: from ds4.des.no (smtp.des.no [194.63.250.102]) by smtp.des.no (Postfix) with ESMTP id 32B5467D5; Mon, 11 Jun 2012 09:47:18 +0000 (UTC) Received: by ds4.des.no (Postfix, from userid 1001) id E7A569EDA; Mon, 11 Jun 2012 11:47:17 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Lars Engels References: <86r4tqotjo.fsf@ds4.des.no> <6E26E03B-8D1D-44D3-B94E-0552BE5CA894@FreeBSD.org> <20120610145351.GA1098@reks> <86ehpmp6xq.fsf@ds4.des.no> <20120611093505.GN5592@e-new.0x20.net> Date: Mon, 11 Jun 2012 11:47:17 +0200 In-Reply-To: <20120611093505.GN5592@e-new.0x20.net> (Lars Engels's message of "Mon, 11 Jun 2012 11:35:05 +0200") Message-ID: <86wr3enpsq.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: Damian Weber , freebsd-security@freebsd.org, Gleb Kurtsou , "Simon L. B. Nielsen" Subject: Re: Default password hash X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 11 Jun 2012 09:47:19 -0000 Lars Engels writes: > BTW Solaris 10 and 11 support our Blowfish algorithm, Solaris 10 >=3D 10/= 08 > supports SHA256 and SHA512 and SHA256 was mad the default algorithm in > Solaris 11. > Some Linux variants support Blowfish and from glibc 2.7 on they have > support for SHA256 and SHA512. > > So the least common denominator if we want to use a compatible format is > SHA256/SHA512. SHA512 is the default in RedHat, Fedora, Debian and Ubuntu. I believe SUSE uses Blowfish, but I'm not sure. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no