| Server IP : 178.105.222.151 / Your IP : 216.73.216.38 Web Server : nginx/1.28.3 System : Linux MNK 7.0.0-15-generic #15-Ubuntu SMP PREEMPT_DYNAMIC Wed Apr 22 16:06:43 UTC 2026 x86_64 User : www-data ( 33) PHP Version : 8.5.4 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : OFF Directory : /usr/share/doc/python3-passlib/html/lib/ |
Upload File : |
<!DOCTYPE html>
<html lang="en" data-content_root="../">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>passlib.hash.des_crypt - DES Crypt — Passlib vlatest Documentation</title>
<link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=fa44fd50" />
<link rel="stylesheet" type="text/css" href="../_static/classic.css?v=2bf1fcf8" />
<script src="../_static/documentation_options.js?v=c6e86fd7"></script>
<script src="../_static/doctools.js?v=9bcbadda"></script>
<script src="../_static/sphinx_highlight.js?v=dc90522c"></script>
<link rel="icon" href="../_static/logo.ico"/>
<link rel="index" title="Index" href="../genindex.html" />
<link rel="search" title="Search" href="../search.html" />
<link rel="copyright" title="Copyright" href="../copyright.html" />
<link rel="next" title="passlib.hash.bsdi_crypt - BSDi Crypt" href="passlib.hash.bsdi_crypt.html" />
<link rel="prev" title="passlib.hash.sun_md5_crypt - Sun MD5 Crypt" href="passlib.hash.sun_md5_crypt.html" />
</head><body>
<div class="related" role="navigation" aria-label="Related">
<h3>Navigation</h3>
<ul>
<li class="right" style="margin-right: 10px">
<a href="../genindex.html" title="General Index"
accesskey="I">index</a></li>
<li class="right" >
<a href="../py-modindex.html" title="Python Module Index"
>modules</a> |</li>
<li class="right" >
<a href="passlib.hash.bsdi_crypt.html" title="passlib.hash.bsdi_crypt - BSDi Crypt"
accesskey="N">next</a> |</li>
<li class="right" >
<a href="passlib.hash.sun_md5_crypt.html" title="passlib.hash.sun_md5_crypt - Sun MD5 Crypt"
accesskey="P">previous</a> |</li>
<li class="nav-item nav-item-0"><a href="../contents.html">Passlib latest Documentation</a> »</li>
<li class="nav-item nav-item-1"><a href="index.html" >API Reference</a> »</li>
<li class="nav-item nav-item-2"><a href="passlib.hash.html" accesskey="U"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.hash</span></code> - Password Hashing Schemes</a> »</li>
<li class="nav-item nav-item-this"><a href=""><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.des_crypt</span></code> - DES Crypt</a></li>
</ul>
</div>
<div class="document">
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="passlib-hash-des-crypt-des-crypt">
<h1><a class="reference internal" href="#passlib.hash.des_crypt" title="passlib.hash.des_crypt"><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.des_crypt</span></code></a> - DES Crypt<a class="headerlink" href="#passlib-hash-des-crypt-des-crypt" title="Link to this heading">¶</a></h1>
<div class="block-title admonition danger">
<p class="admonition-title">Danger</p>
<p><strong>This algorithm is dangerously insecure by modern standards.</strong>
It is trivially broken, and should not be used if at all possible.
For new code, see the list of <a class="reference internal" href="../narr/quickstart.html#recommended-hashes"><span class="std std-ref">recommended hashes</span></a>.</p>
</div>
<p>This class implements the original DES-based Unix Crypt algorithm.
While no longer in active use in most places,
it is supported for legacy purposes by many Unix flavors.
It can used directly as follows:</p>
<div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="gp">>>> </span><span class="kn">from</span> <span class="nn">passlib.hash</span> <span class="kn">import</span> <span class="n">des_crypt</span>
<span class="gp">>>> </span><span class="c1"># generate new salt, hash password</span>
<span class="gp">>>> </span><span class="nb">hash</span> <span class="o">=</span> <span class="n">des_crypt</span><span class="o">.</span><span class="n">hash</span><span class="p">(</span><span class="s2">"password"</span><span class="p">)</span>
<span class="go">'JQMuyS6H.AGMo'</span>
<span class="gp">>>> </span><span class="c1"># verify the password</span>
<span class="gp">>>> </span><span class="n">des_crypt</span><span class="o">.</span><span class="n">verify</span><span class="p">(</span><span class="s2">"password"</span><span class="p">,</span> <span class="nb">hash</span><span class="p">)</span>
<span class="go">True</span>
<span class="gp">>>> </span><span class="n">des_crypt</span><span class="o">.</span><span class="n">verify</span><span class="p">(</span><span class="s2">"letmein"</span><span class="p">,</span> <span class="nb">hash</span><span class="p">)</span>
<span class="go">False</span>
</pre></div>
</div>
<div class="admonition seealso">
<p class="admonition-title">See also</p>
<p>the generic <a class="reference internal" href="../narr/hash-tutorial.html#password-hash-examples"><span class="std std-ref">PasswordHash usage examples</span></a></p>
</div>
<section id="interface">
<h2>Interface<a class="headerlink" href="#interface" title="Link to this heading">¶</a></h2>
<dl class="py class">
<dt class="sig sig-object py" id="passlib.hash.des_crypt">
<em class="property"><span class="k"><span class="pre">class</span></span><span class="w"> </span></em><span class="sig-prename descclassname"><span class="pre">passlib.hash.</span></span><span class="sig-name descname"><span class="pre">des_crypt</span></span><a class="headerlink" href="#passlib.hash.des_crypt" title="Link to this definition">¶</a></dt>
<dd><p>This class implements the des-crypt password hash, and follows the <a class="reference internal" href="passlib.ifc.html#password-hash-api"><span class="std std-ref">PasswordHash API</span></a>.</p>
<p>It supports a fixed-length salt.</p>
<p>The <a class="reference internal" href="passlib.ifc.html#passlib.ifc.PasswordHash.using" title="passlib.ifc.PasswordHash.using"><code class="xref py py-meth docutils literal notranslate"><span class="pre">using()</span></code></a> method accepts the following optional keywords:</p>
<dl class="field-list simple">
<dt class="field-odd">Parameters<span class="colon">:</span></dt>
<dd class="field-odd"><ul class="simple">
<li><p><strong>salt</strong> (<em>str</em>) – Optional salt string.
If not specified, one will be autogenerated (this is recommended).
If specified, it must be 2 characters, drawn from the regexp range <code class="docutils literal notranslate"><span class="pre">[./0-9A-Za-z]</span></code>.</p></li>
<li><p><strong>truncate_error</strong> (<em>bool</em>) – <p>By default, des_crypt will silently truncate passwords larger than 8 bytes.
Setting <code class="docutils literal notranslate"><span class="pre">truncate_error=True</span></code> will cause <a class="reference internal" href="passlib.ifc.html#passlib.ifc.PasswordHash.hash" title="passlib.ifc.PasswordHash.hash"><code class="xref py py-meth docutils literal notranslate"><span class="pre">hash()</span></code></a>
to raise a <a class="reference internal" href="passlib.exc.html#passlib.exc.PasswordTruncateError" title="passlib.exc.PasswordTruncateError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">PasswordTruncateError</span></code></a> instead.</p>
<div class="versionadded">
<p><span class="versionmodified added">Added in version 1.7.</span></p>
</div>
</p></li>
<li><p><strong>relaxed</strong> (<em>bool</em>) – <p>By default, providing an invalid value for one of the other
keywords will result in a <code class="xref py py-exc docutils literal notranslate"><span class="pre">ValueError</span></code>. If <code class="docutils literal notranslate"><span class="pre">relaxed=True</span></code>,
and the error can be corrected, a <a class="reference internal" href="passlib.exc.html#passlib.exc.PasslibHashWarning" title="passlib.exc.PasslibHashWarning"><code class="xref py py-exc docutils literal notranslate"><span class="pre">PasslibHashWarning</span></code></a>
will be issued instead. Correctable errors include
<code class="docutils literal notranslate"><span class="pre">salt</span></code> strings that are too long.</p>
<div class="versionadded">
<p><span class="versionmodified added">Added in version 1.6.</span></p>
</div>
</p></li>
</ul>
</dd>
</dl>
</dd></dl>
<div class="admonition note">
<p class="admonition-title">Note</p>
<p>This class will use the first available of two possible backends:</p>
<ul class="simple">
<li><p>stdlib <code class="xref py py-func docutils literal notranslate"><span class="pre">crypt()</span></code>, if the host OS supports DES-Crypt (most Unix systems).</p></li>
<li><p>a pure Python implementation of DES-Crypt built into Passlib.</p></li>
</ul>
<p>You can see which backend is in use by calling the <code class="xref py py-meth docutils literal notranslate"><span class="pre">get_backend()</span></code> method.</p>
</div>
</section>
<section id="format">
<h2>Format<a class="headerlink" href="#format" title="Link to this heading">¶</a></h2>
<p>A des-crypt hash string consists of 13 characters, drawn from <code class="docutils literal notranslate"><span class="pre">[./0-9A-Za-z]</span></code>.
The first 2 characters form a <a class="reference internal" href="passlib.utils.binary.html#passlib.utils.binary.h64" title="passlib.utils.binary.h64"><code class="xref py py-data docutils literal notranslate"><span class="pre">hash64</span></code></a>-encoded
12 bit integer used as the salt, with the remaining characters
forming a hash64-encoded 64-bit integer checksum.</p>
<p>A des-crypt configuration string is also accepted by this module,
consists of only the first 2 characters, corresponding to the salt only.</p>
<p>An example hash (of the string <code class="docutils literal notranslate"><span class="pre">password</span></code>) is <code class="docutils literal notranslate"><span class="pre">JQMuyS6H.AGMo</span></code>, where the salt is <code class="docutils literal notranslate"><span class="pre">JQ</span></code>, and the checksum <code class="docutils literal notranslate"><span class="pre">MuyS6H.AGMo</span></code>.</p>
</section>
<section class="html-toggle" id="algorithm">
<h2>Algorithm<a class="headerlink" href="#algorithm" title="Link to this heading">¶</a></h2>
<p>The checksum is formed by a modified version of the DES cipher in encrypt mode:</p>
<ol class="arabic">
<li><p>Given a password string and a salt string.</p></li>
<li><p>The 2 character salt string is decoded to a 12-bit integer salt value;
The salt string uses little-endian <a class="reference internal" href="passlib.utils.binary.html#passlib.utils.binary.h64" title="passlib.utils.binary.h64"><code class="xref py py-data docutils literal notranslate"><span class="pre">hash64</span></code></a>
encoding.</p></li>
<li><p>If the password is less than 8 bytes, it’s NULL padded at the end to 8 bytes.</p></li>
<li><p>The lower 7 bits of the first 8 bytes of the password are used
to form a 56-bit integer; with the first byte providing
the most significant 7 bits, and the 8th byte providing
the least significant 7 bits.</p>
<p>The remainder of the password (if any) is ignored.</p>
</li>
<li><p>25 repeated rounds of modified DES encryption are performed;
starting with a null input block,
and using the 56-bit integer from step 4 as the DES key.</p>
<p>The salt is used to to mutate the normal DES encrypt operation
by swapping bits <code class="samp docutils literal notranslate"><em><span class="pre">i</span></em></code> and <code class="samp docutils literal notranslate"><em><span class="pre">i</span></em><span class="pre">+24</span></code> in the DES E-Box output
if and only if bit <code class="samp docutils literal notranslate"><em><span class="pre">i</span></em></code> is set in the salt value.
Thus, if the salt is set to <code class="docutils literal notranslate"><span class="pre">0</span></code>, normal DES encryption is performed.
(This was intended to prevent optimized implementations
of regular DES encryption to be useful in attacking this algorithm).</p>
</li>
<li><p>The 64-bit result of the last round of step 5 is then
lsb-padded with 2 zero bits.</p></li>
<li><p>The resulting 66-bit integer is encoded in big-endian order using the
<a class="reference internal" href="passlib.utils.binary.html#passlib.utils.binary.h64big" title="passlib.utils.binary.h64big"><code class="xref py py-data docutils literal notranslate"><span class="pre">hash64-big</span></code></a> format.</p></li>
</ol>
</section>
<section id="security-issues">
<h2>Security Issues<a class="headerlink" href="#security-issues" title="Link to this heading">¶</a></h2>
<p>DES-Crypt is no longer considered secure, for a variety of reasons:</p>
<ul class="simple">
<li><p>Its use of the DES stream cipher, which is vulnerable to practical pre-image attacks,
and considered broken, as well as having too-small key and block sizes.</p></li>
<li><p>The 12-bit salt is considered to small to defeat rainbow-table attacks
(most modern algorithms provide at least a 48-bit salt).</p></li>
<li><p>The fact that it only uses the lower 7 bits of the first 8 bytes of the password
results in a dangerously small keyspace which needs to be searched.</p></li>
</ul>
</section>
<section id="deviations">
<h2>Deviations<a class="headerlink" href="#deviations" title="Link to this heading">¶</a></h2>
<p>This implementation of des-crypt differs from others in a few ways:</p>
<ul>
<li><p>Minimum salt string:</p>
<p>Some implementations of des-crypt permit empty and single-character salt strings.
However, behavior in these cases varies wildly;
with implementations returning everything from errors
to incorrect hashes that never validate.
To avoid all this, Passlib will throw an “invalid salt” if the provided
salt string is not at least 2 characters.</p>
</li>
<li><p>Restricted salt string character set:</p>
<p>The underlying algorithm expects salt strings to use the
<a class="reference internal" href="passlib.utils.binary.html#passlib.utils.binary.HASH64_CHARS" title="passlib.utils.binary.HASH64_CHARS"><code class="xref py py-data docutils literal notranslate"><span class="pre">hash64</span></code></a> character set to encode
a 12-bit integer. Many implementations of des-crypt will
accept a salt containing other characters, but
vary wildly in how they are handled, including errors and implementation-specific value mappings.
To avoid all this, Passlib will throw an “invalid salt” if the salt
string contains any non-standard characters.</p>
</li>
<li><p>Unicode Policy:</p>
<p>The original des-crypt algorithm was designed for 7-bit <code class="docutils literal notranslate"><span class="pre">us-ascii</span></code> encoding only
(as evidenced by the fact that it discards the 8th bit of all password bytes).</p>
<p>In order to provide support for unicode strings,
Passlib will encode unicode passwords using <code class="docutils literal notranslate"><span class="pre">utf-8</span></code>
before running them through des-crypt. If a different
encoding is desired by an application, the password should be encoded
before handing it to Passlib.</p>
</li>
</ul>
<p class="rubric">Footnotes</p>
<aside class="footnote-list brackets">
<aside class="footnote brackets" id="id1" role="doc-footnote">
<span class="label"><span class="fn-bracket">[</span>1<span class="fn-bracket">]</span></span>
<p>A java implementation of des-crypt, used as base for Passlib’s pure-python implementation,
can be found at <a class="reference external" href="http://www.dynamic.net.au/christos/crypt/UnixCrypt2.txt">http://www.dynamic.net.au/christos/crypt/UnixCrypt2.txt</a></p>
</aside>
</aside>
</section>
</section>
<div class="clearer"></div>
</div>
</div>
</div>
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<p class="logo"><a href="../contents.html">
<img class="logo" src="../_static/masthead.png" alt="Logo of Passlib"/>
</a></p>
<search id="searchbox" style="display: none" role="search">
<h3 id="searchlabel">Quick search</h3>
<div class="searchformwrapper">
<form class="search" action="../search.html" method="get">
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false"/>
<input type="submit" value="Go" />
</form>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script>
<h3><a href="../contents.html">Table of Contents</a></h3>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="../index.html">Introduction</a></li>
<li class="toctree-l1"><a class="reference internal" href="../narr/index.html">Walkthrough & Tutorials</a></li>
<li class="toctree-l1 current"><a class="reference internal" href="index.html">API Reference</a><ul class="current">
<li class="toctree-l2"><a class="reference internal" href="passlib.apache.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.apache</span></code> - Apache Password Files</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.apps.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.apps</span></code> - Helpers for various applications</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.context.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.context</span></code> - CryptContext Hash Manager</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.crypto.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.crypto</span></code> - Cryptographic Helper Functions</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.exc.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.exc</span></code> - Exceptions and warnings</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.ext.django.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.ext.django</span></code> - Django Password Hashing Plugin</a></li>
<li class="toctree-l2 current"><a class="reference internal" href="passlib.hash.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.hash</span></code> - Password Hashing Schemes</a><ul class="current">
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#overview">Overview</a></li>
<li class="toctree-l3 current"><a class="reference internal" href="passlib.hash.html#unix-hashes">Unix Hashes</a><ul class="current">
<li class="toctree-l4"><a class="reference internal" href="passlib.hash.html#active-unix-hashes">Active Unix Hashes</a></li>
<li class="toctree-l4"><a class="reference internal" href="passlib.hash.html#deprecated-unix-hashes">Deprecated Unix Hashes</a></li>
<li class="toctree-l4 current"><a class="reference internal" href="passlib.hash.html#archaic-unix-hashes">Archaic Unix Hashes</a></li>
</ul>
</li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#other-modular-crypt-hashes">Other “Modular Crypt” Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#ldap-rfc2307-hashes">LDAP / RFC2307 Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#sql-database-hashes">SQL Database Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#ms-windows-hashes">MS Windows Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#cisco-hashes">Cisco Hashes</a></li>
<li class="toctree-l3"><a class="reference internal" href="passlib.hash.html#other-hashes">Other Hashes</a></li>
</ul>
</li>
<li class="toctree-l2"><a class="reference internal" href="passlib.hosts.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.hosts</span></code> - OS Password Handling</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.ifc.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.ifc</span></code> – Password Hash Interface</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.pwd.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.pwd</span></code> – Password generation helpers</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.registry.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.registry</span></code> - Password Handler Registry</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.totp.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.totp</span></code> – TOTP / Two Factor Authentication</a></li>
<li class="toctree-l2"><a class="reference internal" href="passlib.utils.html"><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.utils</span></code> - Helper Functions</a></li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="../other.html">Other Documentation</a></li>
</ul>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="related" role="navigation" aria-label="Related">
<h3>Navigation</h3>
<ul>
<li class="right" style="margin-right: 10px">
<a href="../genindex.html" title="General Index"
>index</a></li>
<li class="right" >
<a href="../py-modindex.html" title="Python Module Index"
>modules</a> |</li>
<li class="right" >
<a href="passlib.hash.bsdi_crypt.html" title="passlib.hash.bsdi_crypt - BSDi Crypt"
>next</a> |</li>
<li class="right" >
<a href="passlib.hash.sun_md5_crypt.html" title="passlib.hash.sun_md5_crypt - Sun MD5 Crypt"
>previous</a> |</li>
<li class="nav-item nav-item-0"><a href="../contents.html">Passlib latest Documentation</a> »</li>
<li class="nav-item nav-item-1"><a href="index.html" >API Reference</a> »</li>
<li class="nav-item nav-item-2"><a href="passlib.hash.html" ><code class="xref py py-mod docutils literal notranslate"><span class="pre">passlib.hash</span></code> - Password Hashing Schemes</a> »</li>
<li class="nav-item nav-item-this"><a href=""><code class="xref py py-class docutils literal notranslate"><span class="pre">passlib.hash.des_crypt</span></code> - DES Crypt</a></li>
</ul>
</div>
<div class="footer" role="contentinfo">
© <a href="../copyright.html">Copyright</a> 2008-2025, Assurance Technologies, LLC. Last Updated 2025-12-21.
Created using <a href="https://www.sphinx-doc.org/">Sphinx</a> 8.2.3.
</div>
</body>
</html>