[RFC][PATCH][BZ 2100] blowfish support in libcrypt

Thorsten Kukuk kukuk@suse.de
Tue Jun 20 11:33:00 GMT 2017


On Thu, Jun 01, Björn Esser wrote:

> Look at OpenBSD, SUSE, OpenWall, etc. still using bcrypt as the default password hashing algorithm.

At least for SUSE this is not correct.
Blowfish is only there for compatibility reasons with existing passwords.
With the default configuration, you cannot even create new passwords with blowfish
since many years.
The last time we discussed the topic with the blowfish author, he was surprised
that there is still somebody using it.

  Thorsten

-- 
Thorsten Kukuk, Distinguished Engineer, Senior Architect SLES & CaaSP
SUSE LINUX GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany
GF: Felix Imendoerffer, Jane Smithard, Graham Norton, HRB 21284 (AG Nuernberg)



More information about the Libc-alpha mailing list