all lists on lists.proxmox.com
 help / color / mirror / Atom feed
* [PATCH docs 0/2] update documentation to show that yescrypt is used
@ 2026-10-09 12:27 Shannon Sterz
  2026-10-09 12:27 ` [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt Shannon Sterz
  2026-10-09 12:27 ` [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes Shannon Sterz
  0 siblings, 2 replies; 3+ messages in thread
From: Shannon Sterz @ 2026-10-09 12:27 UTC (permalink / raw)
  To: pve-devel

instead of the sha256crypt scheme. also added a note on how to
remediate older accounts potentially still using that scheme. added
that as a second commit so it can optionally be dropped (or squashed
if preferred).

Shannon Sterz (2):
  pveum: document that the pve realm now uses yescrypt
  pveum: note that passwords set with old versions may use insecure
    hashes

 pveum.adoc | 18 +++++++++++++-----
 1 file changed, 13 insertions(+), 5 deletions(-)

--
2.47.3





^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt
  2026-10-09 12:27 [PATCH docs 0/2] update documentation to show that yescrypt is used Shannon Sterz
@ 2026-10-09 12:27 ` Shannon Sterz
  2026-10-09 12:27 ` [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes Shannon Sterz
  1 sibling, 0 replies; 3+ messages in thread
From: Shannon Sterz @ 2026-10-09 12:27 UTC (permalink / raw)
  To: pve-devel

this has been the case for over a year already [1], but the
documentation was never updated. it came up as part of an internal
process where this discrepancy caused a misunderstanding.

[1]: https://git.proxmox.com/?p=pve-common.git;a=commit;h=6cbbb1863d

Signed-off-by: Shannon Sterz <s.sterz@proxmox.com>
---
 pveum.adoc | 11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

diff --git a/pveum.adoc b/pveum.adoc
index d089cb6..53cb992 100644
--- a/pveum.adoc
+++ b/pveum.adoc
@@ -147,11 +147,12 @@ these users to log in via their system username and password.
 {pve} Authentication Server::
 
 This is a Unix-like password store, which stores hashed passwords in
-`/etc/pve/priv/shadow.cfg`. Passwords are hashed using the SHA-256 hashing
-algorithm. This is the most convenient realm for small-scale (or even
-mid-scale) installations, where users do not need access to anything outside of
-{pve}. In this case, users are fully managed by {pve} and are able to change
-their own passwords via the GUI.
+`/etc/pve/priv/shadow.cfg`. Passwords are hashed and salted using the yescrypt
+algorithm footnote:[yescrypt https://www.openwall.com/yescrypt/]. It provides
+strong protections against offline password cracking attempts. This realm is the
+most convenient realm for small-scale (or even mid-scale) installations, where
+users do not need access to anything outside of {pve}. In this case, users are
+fully managed by {pve} and are able to change their own passwords via the GUI.
 
 LDAP::
 
-- 
2.47.3





^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes
  2026-10-09 12:27 [PATCH docs 0/2] update documentation to show that yescrypt is used Shannon Sterz
  2026-10-09 12:27 ` [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt Shannon Sterz
@ 2026-10-09 12:27 ` Shannon Sterz
  1 sibling, 0 replies; 3+ messages in thread
From: Shannon Sterz @ 2026-10-09 12:27 UTC (permalink / raw)
  To: pve-devel

and describe how to remidiate that issue.

Signed-off-by: Shannon Sterz <s.sterz@proxmox.com>
---

Notes:
    we may want to implement a scheme similar to pbs and pdm where
    passwords are updated to the latest hashing scheme on log in,
    requiring less user interaction.

 pveum.adoc | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/pveum.adoc b/pveum.adoc
index 53cb992..f3b68c2 100644
--- a/pveum.adoc
+++ b/pveum.adoc
@@ -154,6 +154,13 @@ most convenient realm for small-scale (or even mid-scale) installations, where
 users do not need access to anything outside of {pve}. In this case, users are
 fully managed by {pve} and are able to change their own passwords via the GUI.
 
+NOTE: Passwords created with versions of Proxmox VE that used a
+libpve-common-perl version older than 8.3.1 used a hashing scheme based on
+SHA-256 that is now considered insecure. If the file `/etc/pve/priv/shadow.cfg`
+shows a password hash starting with `$5$` for an account, setting a new password
+for that account is recommended. The new password will then be stored using
+yescrypt (the hash will start with `$y$`).
+
 LDAP::
 
 LDAP (Lightweight Directory Access Protocol) is an open, cross-platform protocol
-- 
2.47.3





^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-09 12:28 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-09 12:27 [PATCH docs 0/2] update documentation to show that yescrypt is used Shannon Sterz
2026-10-09 12:27 ` [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt Shannon Sterz
2026-10-09 12:27 ` [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes Shannon Sterz

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal