-
☆ A M B ☆
- 116 Posts
Hello,
Is it possible to force the MD5 hash on modx Revolution?
Thank You
-
☆ A M B ☆
- 24,524 Posts
Yes. Set the user's hash_class to "hashing.modMD5". For example,
UPDATE modx_users SET hash_class = 'hashing.modMD5', password = MD5('the-new-password') WHERE username = 'theusername';
https://rtfm.modx.com/revolution/2.x/administering-your-site/security/troubleshooting-security/resetting-a-user-password-manually
You might be able to create a new System Setting, hash_class, with a value of modMD5, but I'm not sure that will change the default MODX hashing method.
-
☆ A M B ☆
- 116 Posts
Quote from: sottwell at Sep 22, 2015, 07:47 AMYes. Set the user's hash_class to "hashing.modMD5". For example,
UPDATE modx_users SET hash_class = 'hashing.modMD5', password = MD5('the-new-password') WHERE username = 'theusername';
https://rtfm.modx.com/revolution/2.x/administering-your-site/security/troubleshooting-security/resetting-a-user-password-manually
You might be able to create a new System Setting, hash_class, with a value of modMD5, but I'm not sure that will change the default MODX hashing method.
Thank You sottwell.
I want this for the accounts created in the manager, but the system setting hash_class doesn't work...
-
☆ A M B ☆
- 24,524 Posts
The only other thing that I can think of is to go into your database and change the default value for the hash_class field in the users table from hashing.modPBKDF2 to hashing.modMD5.
This really isn't a good idea, the MD5 hashing algorithm has long since been broken. What is the purpose of this?
-
☆ A M B ☆
- 116 Posts
I tried but it didn't work.
Because of a timing problem with another application. It's waiting to change the operation.
-
☆ A M B ☆
- 24,524 Posts
Ok, I spoke to some people, and the only way to do this is to extend modUser. That's not something I could be of any help with.
https://rtfm.modx.com/revolution/2.x/developing-in-modx/advanced-development/extending-moduser
-
☆ A M B ☆
- 24,524 Posts
If you look at core/model/schema/modx.mysql.schema.xml at line 1243 (for MODX Revolution 2.4.0) you'll find the schema for the modUser class.
Line 1251 defines the hash_class field and its default value. So in extending modUser you would need to override that in your custom class's schema file. But that's all I know about it.
-
☆ A M B ☆
- 116 Posts
Thank you for your help, I'll try it