From 7286c2b90c0844d978cb498f656b36386b688024 Mon Sep 17 00:00:00 2001 From: Adam Date: Sun, 20 Apr 2014 15:19:47 -0400 Subject: Deprecate enc_old, enc_md5, and enc_sha1 --- data/example.conf | 19 +++---------------- modules/encryption/enc_md5.cpp | 3 ++- modules/encryption/enc_old.cpp | 2 ++ modules/encryption/enc_sha1.cpp | 3 ++- 4 files changed, 9 insertions(+), 18 deletions(-) diff --git a/data/example.conf b/data/example.conf index a4f3ac886..e131aed23 100644 --- a/data/example.conf +++ b/data/example.conf @@ -1191,23 +1191,10 @@ module * encrypted by this module. Old passwords stored in another encryption method are * automatically re-encrypted by the primary encryption module on next identify. * - * NOTE: enc_old is Anope's previous (broken) MD5 implementation which is present in - * versions prior to Anope 1.7.17. If your databases were made using that module, - * use this and not enc_md5. - * - * NOTE: enc_sha1 relies on how the OS stores 2+ byte data internally, and is - * potentially broken when moving between 2 different OSes, such as moving from - * Linux to Windows. It is recommended that you use enc_sha256 instead if you want - * to use an SHA-based encryption. If you choose to do so, it is also recommended - * that you first try to get everyone's passwords converted to enc_sha256 before - * switching OSes by placing enc_sha256 at the beginning of the list. - * */ #module { name = "enc_bcrypt" } module { name = "enc_sha256" } -#module { name = "enc_md5" } -#module { name = "enc_sha1" } /* * When using enc_none, passwords will be stored without encryption. This isn't secure @@ -1216,10 +1203,10 @@ module { name = "enc_sha256" } #module { name = "enc_none" } /* - * enc_old is Anope's previous (broken) MD5 implementation used from 1.4.x to 1.7.16. - * If your databases were made using that module, load it here to allow conversion to the primary - * encryption method. + * [DEPRECATED] Deprecated encryption modules. */ +#module { name = "enc_md5" } +#module { name = "enc_sha1" } #module { name = "enc_old" } diff --git a/modules/encryption/enc_md5.cpp b/modules/encryption/enc_md5.cpp index 838c5712f..108fb2504 100644 --- a/modules/encryption/enc_md5.cpp +++ b/modules/encryption/enc_md5.cpp @@ -349,7 +349,8 @@ class EMD5 : public Module , EventHook("OnCheckAuthentication") , md5provider(this) { - + if (ModuleManager::FindFirstOf(ENCRYPTION) == this) + throw ModuleException("enc_md5 is deprecated and can not be used as a primary encryption method"); } EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) override diff --git a/modules/encryption/enc_old.cpp b/modules/encryption/enc_old.cpp index b885eb777..671921c72 100644 --- a/modules/encryption/enc_old.cpp +++ b/modules/encryption/enc_old.cpp @@ -48,6 +48,8 @@ class EOld : public Module , EventHook("OnCheckAuthentication") , oldmd5provider(this) { + if (ModuleManager::FindFirstOf(ENCRYPTION) == this) + throw ModuleException("enc_old is deprecated and can not be used as a primary encryption method"); ModuleManager::LoadModule("enc_md5", User::Find(creator)); if (!md5) diff --git a/modules/encryption/enc_sha1.cpp b/modules/encryption/enc_sha1.cpp index f65b5d5ea..df7de4f72 100644 --- a/modules/encryption/enc_sha1.cpp +++ b/modules/encryption/enc_sha1.cpp @@ -204,7 +204,8 @@ class ESHA1 : public Module , EventHook("OnCheckAuthentication") , sha1provider(this) { - + if (ModuleManager::FindFirstOf(ENCRYPTION) == this) + throw ModuleException("enc_sha1 is deprecated and can not be used as a primary encryption method"); } EventReturn OnEncrypt(const Anope::string &src, Anope::string &dest) override -- cgit