[SR-Users] using bcrypt passwd hashing

Walter Martín Villalba wvillalba at gmail.com
Sat Nov 11 01:11:26 CET 2017


Hello,

I did some searches online and talked to some colleagues and it seems
Kamailio only supports the traditional HTTP digest authentication, which
uses MD5. I would like to know if any of you has been successful in using
bcrypt/scrypt/pbkdf2 passwd hashing, instead of MD5, which has been deemed
as obsolete and insecure a long time ago. Perhaps you've written your own
auth module, or just modified the config script to call some other
credential checking routine using a custom python/perl script (I'm thinking
of doing the latter, of nothing better is available).

If any of you have done something like this, using bcrypt or any other
current and secure hashing algorithm, I would appreciate some guidance.  If
you haven't, aren't you concerned about storing MD5 password hashes in your
database?

Note: if I can't find a good answer using this list, I will try the
developer's list next.

Thanks in advance,

Martín.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.kamailio.org/pipermail/sr-users/attachments/20171110/2efa5463/attachment.html>


More information about the sr-users mailing list