summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAdam <Adam@anope.org>2014-04-20 15:19:47 -0400
committerAdam <Adam@anope.org>2014-04-20 15:19:47 -0400
commit7286c2b90c0844d978cb498f656b36386b688024 (patch)
treebd3eacf22314dd8a2e552ccb20837b679dde15e8
parent26ac315192e0d8a04d50e910697ab794eedf0cc1 (diff)
Deprecate enc_old, enc_md5, and enc_sha1
-rw-r--r--data/example.conf19
-rw-r--r--modules/encryption/enc_md5.cpp3
-rw-r--r--modules/encryption/enc_old.cpp2
-rw-r--r--modules/encryption/enc_sha1.cpp3
4 files changed, 9 insertions, 18 deletions
diff --git a/data/example.conf b/data/example.conf
index a4f3ac886..e131aed23 100644
--- a/data/example.conf
+++ b/data/example.conf
@@ -1191,23 +1191,10 @@ module
* encrypted by this module. Old passwords stored in another encryption method are
* automatically re-encrypted by the primary encryption module on next identify.
*
- * NOTE: enc_old is Anope's previous (broken) MD5 implementation which is present in
- * versions prior to Anope 1.7.17. If your databases were made using that module,
- * use this and not enc_md5.
- *
- * NOTE: enc_sha1 relies on how the OS stores 2+ byte data internally, and is
- * potentially broken when moving between 2 different OSes, such as moving from
- * Linux to Windows. It is recommended that you use enc_sha256 instead if you want
- * to use an SHA-based encryption. If you choose to do so, it is also recommended
- * that you first try to get everyone's passwords converted to enc_sha256 before
- * switching OSes by placing enc_sha256 at the beginning of the list.
- *
*/
#module { name = "enc_bcrypt" }
module { name = "enc_sha256" }
-#module { name = "enc_md5" }
-#module { name = "enc_sha1" }
/*
* When using enc_none, passwords will be stored without encryption. This isn't secure
@@ -1216,10 +1203,10 @@ module { name = "enc_sha256" }
#module { name = "enc_none" }
/*
- * enc_old is Anope's previous (broken) MD5 implementation used from 1.4.x to 1.7.16.
- * If your databases were made using that module, load it here to allow conversion to the primary
- * encryption method.
+ * [DEPRECATED] Deprecated encryption modules.
*/
+#module { name = "enc_md5" }
+#module { name = "enc_sha1" }
#module { name = "enc_old" }
diff --git a/modules/encryption/enc_md5.cpp b/modules/encryption/enc_md5.cpp
index 838c5712f..108fb2504 100644
--- a/modules/encryption/enc_md5.cpp
+++ b/modules/encryption/enc_md5.cpp
@@ -349,7 +349,8 @@ class EMD5 : public Module
, EventHook<Event::CheckAuthentication>("OnCheckAuthentication")
, md5provider(this)
{
-
+ if (ModuleManager::FindFirstOf(ENCRYPTION) == this)
+ throw ModuleException("enc_md5 is deprecated and can not be used as a primary encryption method");
}
EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) override
diff --git a/modules/encryption/enc_old.cpp b/modules/encryption/enc_old.cpp
index b885eb777..671921c72 100644
--- a/modules/encryption/enc_old.cpp
+++ b/modules/encryption/enc_old.cpp
@@ -48,6 +48,8 @@ class EOld : public Module
, EventHook<Event::CheckAuthentication>("OnCheckAuthentication")
, oldmd5provider(this)
{
+ if (ModuleManager::FindFirstOf(ENCRYPTION) == this)
+ throw ModuleException("enc_old is deprecated and can not be used as a primary encryption method");
ModuleManager::LoadModule("enc_md5", User::Find(creator));
if (!md5)
diff --git a/modules/encryption/enc_sha1.cpp b/modules/encryption/enc_sha1.cpp
index f65b5d5ea..df7de4f72 100644
--- a/modules/encryption/enc_sha1.cpp
+++ b/modules/encryption/enc_sha1.cpp
@@ -204,7 +204,8 @@ class ESHA1 : public Module
, EventHook<Event::CheckAuthentication>("OnCheckAuthentication")
, sha1provider(this)
{
-
+ if (ModuleManager::FindFirstOf(ENCRYPTION) == this)
+ throw ModuleException("enc_sha1 is deprecated and can not be used as a primary encryption method");
}
EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) override