MAN page from Old RedHat 6.X perl-Crypt-UnixCrypt-1.0-6.i386.rpm
UnixCrypt
Section: User Contributed Perl Documentation (3)
Updated: perl 5.005, patch 03
Index NAME
Crypt::UnixCrypt - perl-only implementation of the
crypt function.
SYNOPSIS
use Crypt::UnixCrypt; $hashed = crypt($plaintext,$salt);
# always use this module's crypt BEGIN { $Crypt::UnixCrpyt::OVERRIDE_BUILTIN = 1 } use Crypt::UnixCrypt; DESCRIPTION
This module is for all those poor souls whose perl port answers to theuse of
crypt() with the message `The
crypt() function is unimplementeddue to excessive paranoia.'.
This module won't overload a built-in crypt() unless forced by a truevalue of the variable $Crypt::UnixCrypt::OVERRIDE_BUILTIN.
If you use this module, you probably neither have a built-in crypt()function nor a the crypt(3) manpage manpage; so I'll supply the appropriate portionsof its description (from my Linux system) here:
crypt is the password encryption function. It is based on the DataEncryption Standard algorithm with variations intended (among otherthings) to discourage use of hardware implementations of a key search.
$plaintext is a user's typed password.
$salt is a two-character string chosen from the set [a-zA-Z0-9./]. Thisstring is used to perturb the algorithm in one of 4096 different ways.
By taking the lowest 7 bit of each character of $plaintext (filling it upto 8 characters with zeros, if needed), a 56-bit key is obtained. This56-bit key is used to encrypt repeatedly a constant string (usually astring consisting of all zeros). The returned value points to theencrypted password, a series of 13 printable ASCII characters (the firsttwo characters represent the salt itself).
Warning: The key space consists of 2**56 equal 7.2e16 possible values.Exhaustive searches of this key space are possible using massivelyparallel computers. Software, such as crack(1), is available which willsearch the portion of this key space that is generally used by humansfor passwords. Hence, password selection should, at minimum, avoidcommon words and names. The use of a passwd(1) program that checks forcrackable passwords during the selection process is recommended.
The DES algorithm itself has a few quirks which make the use of thecrypt(3) interface a very poor choice for anything other than passwordauthentication. If you are planning on using the crypt(3) interface fora cryptography project, don't do it: get a good book on encryption andone of the widely available DES libraries.
COPYRIGHT
This module is free software; you may redistribute it and/or modify itunder the same terms as Perl itself.
AUTHORS
Written by Martin Vorlaender, martinAATTradiogaga.harz.de, 11-DEC-1997.Based upon Java source code written by jdumasAATTzgs.com, which in turn isbased upon C source code written by Eric Young, eayAATTpsych.uq.oz.au.
CAVEATS
In extreme situations, this function doesn't behave like
crypt(3),e.g. when called with a salt not in [A-Za-z0-9./]{2}.
SEE ALSO
perl(1),
perlfunc(1),
crypt(3).
Index
- NAME
- SYNOPSIS
- DESCRIPTION
- COPYRIGHT
- AUTHORS
- CAVEATS
- SEE ALSO
This document was created byman2html,using the manual pages.