Changes between Version 1 and Version 3 of Ticket #37375
- Timestamp:
- Sep 28, 2026, 8:41:00 AM (75 minutes ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Ticket #37375
- Property Summary `ScryptPasswordHasher` cannot verify hashes with non-default derived key lengths → ScryptPasswordHasher cannot verify hashes with derived key lengths greater than 64 bytes
-
Ticket #37375 – Description
v1 v3 9 9 (https://goauthentik.io), where imported scrypt hashes may come from systems 10 10 using different `dklen` values. 11 12 For example, using the same password, salt, N, r, and p values: 13 14 {{{ 15 scrypt$16384$django-scrypt-example$8$1$D5reUgzHkb7jsUr+tu+tLDdM7Zx9ogzquC0AJYM1U6irspdgjDMDL7GforSHakP8eTjb3aDsBw+VLv+odzzPpA== 16 scrypt$16384$django-scrypt-example$8$1$D5reUgzHkb7jsUr+tu+tLDdM7Zx9ogzquC0AJYM1U6irspdgjDMDL7GforSHakP8eTjb3aDsBw+VLv+odzzPpDHtdiQLBYg3cABNaUmj/LOy7C0gbqe9Tt3TA/GAuuaql9RhoeGh57L7aDdxGhddkCbrwxLVvzJxa6YRW1XqdCs= 17 }}} 18 19 The first uses `dklen=64` and can be verified by Django. The second uses 20 `dklen=128` and currently cannot, even though all other scrypt parameters are 21 the same. 11 22 12 23 Django should probably keep 64 bytes as the minimum accepted derived key