md5crypt - MD5-based password encryption

package require Tcl 8.5 9
package require md5 2.0
package require md5crypt ?1.2.0?

::md5crypt::md5crypt password salt
::md5crypt::aprcrypt password salt
::md5crypt::salt ?length?


This package provides an implementation of the MD5-crypt password encryption algorithm as pioneered by FreeBSD and currently in use as a replacement for the unix crypt(3) function in many modern systems. An implementation of the closely related Apache MD5-crypt is also available. The output of these commands are compatible with the BSD and OpenSSL implementation of md5crypt and the Apache 2 htpasswd program.



The salt passed to either of the encryption schemes implemented here is checked to see if it begins with the encryption scheme magic string (either "$1$" for MD5-crypt or "$apr1$" for Apache crypt). If so, this is removed. The remaining characters up to the next $ and up to a maximum of 8 characters are then used as the salt. The salt text should probably be restricted to the set of ASCII alphanumeric characters plus "./" (dot and forward-slash) - this is to preserve maximum compatibility with the unix password file format.

If a password is being generated rather than checked from a password file then the salt command may be used to generate a random salt.


% md5crypt::md5crypt password 01234567

% md5crypt::aprcrypt password 01234567

% md5crypt::md5crypt password [md5crypt::salt]

hashing, md5, md5crypt, message-digest, security


Hashes, checksums, and encryption


Copyright © 2003, Pat Thoyts