Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow specifying bcrypt version for htpasswd #416

Open
fchan21 opened this issue Oct 18, 2024 · 0 comments
Open

Allow specifying bcrypt version for htpasswd #416

fchan21 opened this issue Oct 18, 2024 · 0 comments

Comments

@fchan21
Copy link

fchan21 commented Oct 18, 2024

Currently, htpasswd only produces version 2a for hashing which is not accepted in more modern systems. There is a minor security concern with using 2a, so 2y is generally favored. While it might be a bit heavy-handed to force htpasswd to use 2y, it should at least be configurable using additional arguments passed in to the htpasswd function.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant