From owner-freebsd-current@FreeBSD.ORG Sat Jun 9 09:28:25 2012 Return-Path: Delivered-To: freebsd-current@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id DD7F0106566B; Sat, 9 Jun 2012 09:28:25 +0000 (UTC) (envelope-from dim@FreeBSD.org) Received: from tensor.andric.com (cl-327.ede-01.nl.sixxs.net [IPv6:2001:7b8:2ff:146::2]) by mx1.freebsd.org (Postfix) with ESMTP id 961DD8FC0A; Sat, 9 Jun 2012 09:28:25 +0000 (UTC) Received: from [IPv6:2001:7b8:3a7:0:ac9c:8782:4659:6790] (unknown [IPv6:2001:7b8:3a7:0:ac9c:8782:4659:6790]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by tensor.andric.com (Postfix) with ESMTPSA id 2067D5C37; Sat, 9 Jun 2012 11:28:24 +0200 (CEST) Message-ID: <4FD3173E.2040505@FreeBSD.org> Date: Sat, 09 Jun 2012 11:28:30 +0200 From: Dimitry Andric Organization: The FreeBSD Project User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20120529 Thunderbird/13.0 MIME-Version: 1.0 To: "O. Hartmann" References: <86r4tqotjo.fsf@ds4.des.no> <4FD2FE87.1060708@zedat.fu-berlin.de> In-Reply-To: <4FD2FE87.1060708@zedat.fu-berlin.de> X-Enigmail-Version: 1.5a1pre Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Cc: =?UTF-8?B?RGFnLUVybGluZyBTbcO4cmdyYXY=?= , freebsd-current@FreeBSD.org, freebsd-security@FreeBSD.org Subject: Re: Default password hash X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 09 Jun 2012 09:28:26 -0000 On 2012-06-09 09:43, O. Hartmann wrote: > On 06/08/12 14:51, Dag-Erling Sm=C3=B8rgrav wrote: >> We still have MD5 as our default password hash, even though known-hash= >> attacks against MD5 are relatively easy these days. We've supported >> SHA256 and SHA512 for many years now, so how about making SHA512 the >> default instead of MD5, like on most Linux distributions? =2E.. > The manpage for login.conf also needs an update. I checked this morning= > and found that thye manpage doesn't even mention hashes apart from des,= > md5 and blf. Dag-Erling fixed this just yesterday :) http://svn.freebsd.org/changeset/base/236751