php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #61619 Bcrypt in crypt() fails for cost value less then 10
Submitted: 2012-04-04 09:12 UTC Modified: 2014-11-18 11:14 UTC
From: e dot zimuel at gmail dot com Assigned: salathe (profile)
Status: Closed Package: Documentation problem
PHP Version: 5.3.10 OS: linux
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: e dot zimuel at gmail dot com
New email:
PHP Version: OS:

 

 [2012-04-04 09:12 UTC] e dot zimuel at gmail dot com
Description:
------------
The bcrypt algorithm in the crypt() function fails for cost values less than 10. In the documentation is written that the values to use are in the range 4-31, this range should be 10-31.

---
From manual page: http://www.php.net/function.crypt#refsect1-function.crypt-description
---


Test script:
---------------
$password= '12345678';
$salt = '1234567890123456789012';
for($i=4;$i<=12;$i++) {
    $hash = crypt($password,'$2a$'.$i.'$'.$salt);
    echo ( strlen($hash)<=13 ? "Fails: $hash \n" : "Ok: $hash\n");
}

Expected result:
----------------
Ok: $2a$4$123456789012345678901u...
Ok: $2a$5$123456789012345678901u...
Ok: $2a$6$123456789012345678901u...
Ok: $2a$7$123456789012345678901u...
Ok: $2a$8$123456789012345678901u...
Ok: $2a$9$123456789012345678901u...
Ok: $2a$10$123456789012345678901uOmjxspUyFLEdp6mxJQ4iRnbKlKw1aH6
Ok: $2a$11$123456789012345678901ubLT1mu4s43rkUv0UK6fLURb3WhhPi1.
Ok: $2a$12$123456789012345678901uwZOx4Im8nWhwn3NpS/SBswvxBysXf5q

Actual result:
--------------
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Fails: $2lH9Bbg1vo/g 
Ok: $2a$10$123456789012345678901uOmjxspUyFLEdp6mxJQ4iRnbKlKw1aH6
Ok: $2a$11$123456789012345678901ubLT1mu4s43rkUv0UK6fLURb3WhhPi1.
Ok: $2a$12$123456789012345678901uwZOx4Im8nWhwn3NpS/SBswvxBysXf5q


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2012-04-07 19:38 UTC] frozenfire@php.net
I understand how you were confused about this, but if you read carefully, it 
does say that the cost parameter is two digits.

Using two digits works correctly for 04-31.

Example:

$password= '12345678';
$salt = '1234567890123456789012';
for($i=4;$i<=31;$i++) {
    $x = sprintf('%1$02d', $i);
    $hash = crypt($password,'$2a$'.$x.'$'.$salt);
    echo ( strlen($hash)<=13 ? "$x Fails: $hash \n" : "$x Ok: $hash\n");
}
 [2012-04-07 19:38 UTC] frozenfire@php.net
-Status: Open +Status: Not a bug
 [2012-04-10 08:24 UTC] e dot zimuel at gmail dot com
Thanks for the clarification. My misunderstanding was about the term 'digit' as integer, that actually is a string of two digit.
 [2012-04-11 07:47 UTC] bjori@php.net
-Status: Not a bug +Status: Re-Opened
 [2012-04-11 07:47 UTC] bjori@php.net
Good point.
Maybe a not clarifying it should be added.
The example already shows 07 being used, but this could be clearer.
 [2014-11-18 11:14 UTC] salathe@php.net
-Status: Re-Opened +Status: Closed -Assigned To: +Assigned To: salathe
 [2014-11-18 11:14 UTC] salathe@php.net
This was fixed years ago.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 00:00:02 2026 UTC