From 047fc190f3b20b43fda4428630f471187258fbb6 Mon Sep 17 00:00:00 2001 From: Aleksander Machniak <alec@alec.pl> Date: Fri, 10 Oct 2014 04:26:51 -0400 Subject: [PATCH] Fix regression in SHAA password generation in ldap driver of password plugin (#1490094) --- CHANGELOG | 1 + plugins/password/drivers/ldap.php | 2 +- 2 files changed, 2 insertions(+), 1 deletions(-) diff --git a/CHANGELOG b/CHANGELOG index adba207..2c688b5 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -2,6 +2,7 @@ =========================== - Fix setting flags on servers with no PERMANENTFLAGS response (#1490087) +- Fix regression in SHAA password generation in ldap driver of password plugin (#1490094) RELEASE 1.0.3 ------------- diff --git a/plugins/password/drivers/ldap.php b/plugins/password/drivers/ldap.php index 7bebc8a..d46da0b 100644 --- a/plugins/password/drivers/ldap.php +++ b/plugins/password/drivers/ldap.php @@ -263,7 +263,7 @@ if (function_exists('mhash') && function_exists('mhash_keygen_s2k')) { $salt = mhash_keygen_s2k(MHASH_SHA1, $password_clear, $salt, 4); - $password = mhash(MHASH_MD5, $password_clear . $salt); + $password = mhash(MHASH_SHA1, $password_clear . $salt); } else if (function_exists('sha1')) { $salt = substr(pack("H*", sha1($salt . $password_clear)), 0, 4); -- Gitblit v1.9.1