[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: The objects...
Well - we still want to look into replacing mod_perl with PHP
authentication - I think this discussion thread is a good place to
discuiss that. Anyone have any thoughts on the matter? If we decide on
crypt (which I think is fine... but md5() would be cool too, and that
would not limit password sizes as strictly right?
Anyway - can we develop php authentication if we go this route? I haven't
looked into it yet - I'm wondering if anyone else has previous experience
in this arena.
Jason
On Sat, Oct 30, 1999 at 02:41:39PM -0700, Micah K Yoder wrote:
> Aaron Turner wrote:
> >
> > Well it turns out that MySQL's encryption is very simular to crypt().
> > If PHP can't encrypt the password natively, then we should probably switch
> > to crypt. Just let me know before anyone starts making changes on this
> > because it WILL break my mod_perl http-auth module. It's pretty easy to
> > fix (I just need to back out of my hacks) but people are going to find
> > themselves locked out.
> >
> > Also, realize there is no way to recover the existing passwords to convert
> > them to crypt(). We're going to have to redo them all.
>
> Ok, I vote for using crypt(). PHP does crypt() and md5(). Any
> preferences, disagreements, flames, etc???
--
Jason
http://vodka.linuxkb.org/~chardros