* [PATCH docs 0/2] update documentation to show that yescrypt is used
@ 2026-10-09 12:27 Shannon Sterz
2026-10-09 12:27 ` [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt Shannon Sterz
2026-10-09 12:27 ` [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes Shannon Sterz
0 siblings, 2 replies; 3+ messages in thread
From: Shannon Sterz @ 2026-10-09 12:27 UTC (permalink / raw)
To: pve-devel
instead of the sha256crypt scheme. also added a note on how to
remediate older accounts potentially still using that scheme. added
that as a second commit so it can optionally be dropped (or squashed
if preferred).
Shannon Sterz (2):
pveum: document that the pve realm now uses yescrypt
pveum: note that passwords set with old versions may use insecure
hashes
pveum.adoc | 18 +++++++++++++-----
1 file changed, 13 insertions(+), 5 deletions(-)
--
2.47.3
^ permalink raw reply [flat|nested] 3+ messages in thread* [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt
2026-10-09 12:27 [PATCH docs 0/2] update documentation to show that yescrypt is used Shannon Sterz
@ 2026-10-09 12:27 ` Shannon Sterz
2026-10-09 12:27 ` [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes Shannon Sterz
1 sibling, 0 replies; 3+ messages in thread
From: Shannon Sterz @ 2026-10-09 12:27 UTC (permalink / raw)
To: pve-devel
this has been the case for over a year already [1], but the
documentation was never updated. it came up as part of an internal
process where this discrepancy caused a misunderstanding.
[1]: https://git.proxmox.com/?p=pve-common.git;a=commit;h=6cbbb1863d
Signed-off-by: Shannon Sterz <s.sterz@proxmox.com>
---
pveum.adoc | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/pveum.adoc b/pveum.adoc
index d089cb6..53cb992 100644
--- a/pveum.adoc
+++ b/pveum.adoc
@@ -147,11 +147,12 @@ these users to log in via their system username and password.
{pve} Authentication Server::
This is a Unix-like password store, which stores hashed passwords in
-`/etc/pve/priv/shadow.cfg`. Passwords are hashed using the SHA-256 hashing
-algorithm. This is the most convenient realm for small-scale (or even
-mid-scale) installations, where users do not need access to anything outside of
-{pve}. In this case, users are fully managed by {pve} and are able to change
-their own passwords via the GUI.
+`/etc/pve/priv/shadow.cfg`. Passwords are hashed and salted using the yescrypt
+algorithm footnote:[yescrypt https://www.openwall.com/yescrypt/]. It provides
+strong protections against offline password cracking attempts. This realm is the
+most convenient realm for small-scale (or even mid-scale) installations, where
+users do not need access to anything outside of {pve}. In this case, users are
+fully managed by {pve} and are able to change their own passwords via the GUI.
LDAP::
--
2.47.3
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes
2026-10-09 12:27 [PATCH docs 0/2] update documentation to show that yescrypt is used Shannon Sterz
2026-10-09 12:27 ` [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt Shannon Sterz
@ 2026-10-09 12:27 ` Shannon Sterz
1 sibling, 0 replies; 3+ messages in thread
From: Shannon Sterz @ 2026-10-09 12:27 UTC (permalink / raw)
To: pve-devel
and describe how to remidiate that issue.
Signed-off-by: Shannon Sterz <s.sterz@proxmox.com>
---
Notes:
we may want to implement a scheme similar to pbs and pdm where
passwords are updated to the latest hashing scheme on log in,
requiring less user interaction.
pveum.adoc | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/pveum.adoc b/pveum.adoc
index 53cb992..f3b68c2 100644
--- a/pveum.adoc
+++ b/pveum.adoc
@@ -154,6 +154,13 @@ most convenient realm for small-scale (or even mid-scale) installations, where
users do not need access to anything outside of {pve}. In this case, users are
fully managed by {pve} and are able to change their own passwords via the GUI.
+NOTE: Passwords created with versions of Proxmox VE that used a
+libpve-common-perl version older than 8.3.1 used a hashing scheme based on
+SHA-256 that is now considered insecure. If the file `/etc/pve/priv/shadow.cfg`
+shows a password hash starting with `$5$` for an account, setting a new password
+for that account is recommended. The new password will then be stored using
+yescrypt (the hash will start with `$y$`).
+
LDAP::
LDAP (Lightweight Directory Access Protocol) is an open, cross-platform protocol
--
2.47.3
^ permalink raw reply related [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-09 12:28 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-09 12:27 [PATCH docs 0/2] update documentation to show that yescrypt is used Shannon Sterz
2026-10-09 12:27 ` [PATCH docs 1/2] pveum: document that the pve realm now uses yescrypt Shannon Sterz
2026-10-09 12:27 ` [PATCH docs 2/2] pveum: note that passwords set with old versions may use insecure hashes Shannon Sterz
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox