php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #61619 Bcrypt in crypt() fails for cost value less then 10
Submitted: 2012-04-04 09:12 UTC Modified: 2014-11-18 11:14 UTC
From: e dot zimuel at gmail dot com Assigned: salathe (profile)
Status: Closed Package: Documentation problem
PHP Version: 5.3.10 OS: linux
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: e dot zimuel at gmail dot com
New email:
PHP Version: OS:

 

 [2012-04-04 09:12 UTC] e dot zimuel at gmail dot com
Description:
------------
The bcrypt algorithm in the crypt() function fails for cost values less than 10. In the documentation is written that the values to use are in the range 4-31, this range should be 10-31.

---
From manual page: http://www.php.net/function.crypt#refsect1-function.crypt-description
---


Test script:
---------------
$password= '12345678';
$salt = '1234567890123456789012';
for($i=4;$i<=12;$i++) {
    $hash = crypt($password,'$2a$'.$i.'$'.$salt);
    echo ( strlen($hash)<=13 ? "Fails: $hash \n" : "Ok: $hash\n");
}

Expected result:
----------------
Ok: $2a$4$123456789012345678901u...
Ok: $2a$5$123456789012345678901u...
Ok: $2a$6$123456789012345678901u...
Ok: $2a$7$123456789012345678901u...
Ok: $2a$8$123456789012345678901u...
Ok: $2a$9$123456789012345678901u...
Ok: $2a$10$123456789012345678901uOmjxspUyFLEdp6mxJQ4iRnbKlKw1aH6
Ok: $2a$11$123456789012345678901ubLT1mu4s43rkUv0UK6fLURb3WhhPi1.
Ok: $2a$12$123456789012345678901uwZOx4Im8nWhwn3NpS/SBswvxBysXf5q

Actual result:
--------------
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Ok: $2a$10$123456789012345678901uOmjxspUyFLEdp6mxJQ4iRnbKlKw1aH6
Ok: $2a$11$123456789012345678901ubLT1mu4s43rkUv0UK6fLURb3WhhPi1.
Ok: $2a$12$123456789012345678901uwZOx4Im8nWhwn3NpS/SBswvxBysXf5q


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2012-04-07 19:38 UTC] frozenfire@php.net
I understand how you were confused about this, but if you read carefully, it 
does say that the cost parameter is two digits.

Using two digits works correctly for 04-31.

Example:

$password= '12345678';
$salt = '1234567890123456789012';
for($i=4;$i<=31;$i++) {
    $x = sprintf('%1$02d', $i);
    $hash = crypt($password,'$2a$'.$x.'$'.$salt);
    echo ( strlen($hash)<=13 ? "$x Fails: $hash \n" : "$x Ok: $hash\n");
}
 [2012-04-07 19:38 UTC] frozenfire@php.net
-Status: Open +Status: Not a bug
 [2012-04-10 08:24 UTC] e dot zimuel at gmail dot com
Thanks for the clarification. My misunderstanding was about the term 'digit' as integer, that actually is a string of two digit.
 [2012-04-11 07:47 UTC] bjori@php.net
-Status: Not a bug +Status: Re-Opened
 [2012-04-11 07:47 UTC] bjori@php.net
Good point.
Maybe a not clarifying it should be added.
The example already shows 07 being used, but this could be clearer.
 [2014-11-18 11:14 UTC] salathe@php.net
-Status: Re-Opened +Status: Closed -Assigned To: +Assigned To: salathe
 [2014-11-18 11:14 UTC] salathe@php.net
This was fixed years ago.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 21:00:02 2026 UTC