From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id BC00E1FF0B0 for ; Fri, 09 Oct 2026 14:28:14 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id C628D2159E; Fri, 09 Oct 2026 14:28:04 +0200 (CEST) From: Shannon Sterz To: pve-devel@lists.proxmox.com Subject: [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes Date: Fri, 9 Oct 2026 14:27:30 +0200 Message-ID: <20261009122729.178682-4-s.sterz@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20261009122729.178682-2-s.sterz@proxmox.com> References: <20261009122729.178682-2-s.sterz@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791548879232 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.797 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: IH2U4TGVES6XGTBKSJX5JXUOTVDF4AFH X-Message-ID-Hash: IH2U4TGVES6XGTBKSJX5JXUOTVDF4AFH X-MailFrom: s.sterz@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: and describe how to remidiate that issue. Signed-off-by: Shannon Sterz --- Notes: we may want to implement a scheme similar to pbs and pdm where passwords are updated to the latest hashing scheme on log in, requiring less user interaction. pveum.adoc | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pveum.adoc b/pveum.adoc index 53cb992..f3b68c2 100644 --- a/pveum.adoc +++ b/pveum.adoc @@ -154,6 +154,13 @@ most convenient realm for small-scale (or even mid-scale) installations, where users do not need access to anything outside of {pve}. In this case, users are fully managed by {pve} and are able to change their own passwords via the GUI. +NOTE: Passwords created with versions of Proxmox VE that used a +libpve-common-perl version older than 8.3.1 used a hashing scheme based on +SHA-256 that is now considered insecure. If the file `/etc/pve/priv/shadow.cfg` +shows a password hash starting with `$5$` for an account, setting a new password +for that account is recommended. The new password will then be stored using +yescrypt (the hash will start with `$y$`). + LDAP:: LDAP (Lightweight Directory Access Protocol) is an open, cross-platform protocol -- 2.47.3