3 ms·
The dev FAQ should contain information on how to safely (and painlessly) migrate from plain-text/MD5/SHA1 to a more secure algorithm.
by vomitcuddle 12y ago
The dev FAQ should contain information on how to safely (and painlessly) migrate from plain-text/MD5/SHA1 to a more secure algorithm.
- thefreeman 12y agoAck, I accidentally down-voted this comment, someone please right my wrong
- huxley 12y agoI think Django's method is a good one to emulate: https://docs.djangoproject.com/en/dev/topics/auth/passwords/ https://docs.djangoproject.com/en/dev/topics/auth/passwords/ A list of password hashers, on successful login the user is upgraded to the top password hasher. Makes it very simple to switch to a new scheme or work factor.
- masklinn 12y agoOutside Django, if you're using Python, there's no excuse to not use passlib[0] whose cryptcontext object[1] handles this situation fantastically: create a cryptcontext with all the hash types you accept as input, and put any "old" hash in the `deprecated` list (or just set `deprecated=['auto']` in 1.6, it'll deprecate any non-default hash — the default hash is the first of the list, or the one passed as the `default` parameter). Then you can just use the relevant method to know that the authentication was successful and you should update the in-db hash: hash = CryptContext( # upgrading from an md5_crypted system ["sha256_crypt", "md5_crypt"], deprecated=['auto']) # in auth code valid, updated = hash.verify_and_update(password, current_hash) if not valid: # error out if updated is not None: # updated is the new hash to set in database [0] https://pythonhosted.org/passlib/ https://pythonhosted.org/passlib/ [1] https://pythonhosted.org/passlib/lib/passlib.context.html?highlight=cryptcontext#passlib.context.CryptContext https://pythonhosted.org/passlib/lib/passlib.context.html?hi...
- omervk 12y agoThat's a good point, but I think it goes a bit over what I was getting at.