From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id D548B1FF0B0 for ; Fri, 09 Oct 2026 14:28:21 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 334D52164A; Fri, 09 Oct 2026 14:28:05 +0200 (CEST) From: Shannon Sterz To: pve-devel@lists.proxmox.com Subject: [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt Date: Fri, 9 Oct 2026 14:27:29 +0200 Message-ID: <20261009122729.178682-3-s.sterz@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20261009122729.178682-2-s.sterz@proxmox.com> References: <20261009122729.178682-2-s.sterz@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791548879160 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.790 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: SIKIDVZ6DWD2USF3G5SA7AMAZ4WDWSKA X-Message-ID-Hash: SIKIDVZ6DWD2USF3G5SA7AMAZ4WDWSKA X-MailFrom: s.sterz@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: this has been the case for over a year already [1], but the documentation was never updated. it came up as part of an internal process where this discrepancy caused a misunderstanding. [1]: https://git.proxmox.com/?p=pve-common.git;a=commit;h=6cbbb1863d Signed-off-by: Shannon Sterz --- pveum.adoc | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/pveum.adoc b/pveum.adoc index d089cb6..53cb992 100644 --- a/pveum.adoc +++ b/pveum.adoc @@ -147,11 +147,12 @@ these users to log in via their system username and password. {pve} Authentication Server:: This is a Unix-like password store, which stores hashed passwords in -`/etc/pve/priv/shadow.cfg`. Passwords are hashed using the SHA-256 hashing -algorithm. This is the most convenient realm for small-scale (or even -mid-scale) installations, where users do not need access to anything outside of -{pve}. In this case, users are fully managed by {pve} and are able to change -their own passwords via the GUI. +`/etc/pve/priv/shadow.cfg`. Passwords are hashed and salted using the yescrypt +algorithm footnote:[yescrypt https://www.openwall.com/yescrypt/]. It provides +strong protections against offline password cracking attempts. This realm is the +most convenient realm for small-scale (or even mid-scale) installations, where +users do not need access to anything outside of {pve}. In this case, users are +fully managed by {pve} and are able to change their own passwords via the GUI. LDAP:: -- 2.47.3