Bug 1714591 - RFE: Please enable argon2 and libsodium support in php
Summary: RFE: Please enable argon2 and libsodium support in php
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: php
Version: 8.1
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: 8.0
Assignee: Remi Collet
QA Contact: RHEL Stacks Subsystem QE
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2019-05-28 11:48 UTC by Neal Gompa
Modified: 2021-01-14 09:38 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-11-11 12:04:19 UTC
Type: Bug
Target Upstream Version:


Attachments (Terms of Use)

Description Neal Gompa 2019-05-28 11:48:07 UTC
Description of problem:
The PHP stack in RHEL 8 has libargon2 and libsodium support disabled, which severely cripples or breaks the ability for PHP web applications to do secure password hashing, among other things.

For example, Symfony-based web applications based on Symfony 3.4 can and will use argon2i algorithms[1], and Symfony-based web applications based on Symfony 4.3 can and will use sodium for this[2].

Please reconsider and enable support for argon2 and sodium in PHP.

[1]: https://symfony.com/blog/new-in-symfony-3-4-argon2i-password-hasher
[2]: https://symfony.com/blog/new-in-symfony-4-3-sodium-password-encoder

Version-Release number of selected component (if applicable):
7.2.11-1.el8

Comment 1 Joe Orton 2019-06-28 13:07:40 UTC
We are not planning to add additional cryptography libraries into RHEL, sorry.

Comment 4 Joe Orton 2019-11-11 12:04:19 UTC
We are not planning to support additional cryptography libraries in RHEL, hence sodium/argon support will remain disabled in PHP.


Note You need to log in before you can comment on or make changes to this bug.