[TYPO3-english] No BE Login in 4.5 under Windows after converting to salted passwords

rsbrux rsbrux at yahoo.com
Sat Sep 7 12:41:22 CEST 2013


Because the status report kept complaining about our insecure use of "unsalted" MD5 hash passwords in the backend (BE) of Typo3 (running under Windows 7), I tried accepting its suggestion to convert to salted passwords (fortunately in our test environment).  Everything appeared to go well, but afterwards I was no longer able to login to the BE (I tried two different accounts).  Both openSSL and rsaauth are loaded, and I didn't notice any error messages anywhere, but I don't have logs anymore as I needed the test environment for other purposes and made a new copy from the production environment.
Before I try this again:
1. I naively assumed that the provided task for switching on salted passwords would take care of everything.  Are there any other steps I should have done after executing it?
2. Is there anything peculiar to the use of Typo3 under Windows, which the task may not have handled properly?   php.ini seems to have all of the correct/necessary parameters for OpenSSL.
3. Is there some diagnostic procedure I can use on the next attempt to make sure that salted passwords have been correctly configured (and to find out what is missing in case they aren't) before logging out of the BE and finding myself unable to log back in?


More information about the TYPO3-english mailing list