Skip to content

Use PBKDF2 password records and harden TLS init - #78

Merged
UldisRinkevichs merged 1 commit into
masterfrom
pbkdf2
Sep 20, 2026
Merged

UldisRinkevichs merged 1 commit into
masterfrom
pbkdf2

Conversation

@hfiref0x

Copy link
Copy Markdown
Owner

Replaced the custom SHA256+Base64 password flow with GnuTLS-based PBKDF2-SHA256 records (scheme$iterations$salt$hash) and added dedicated generate/verify helpers. FTP login (PASS) and fftp -p now use the new record format, with secure zeroing of sensitive buffers.

Also improved startup reliability by making TLS initialization return explicit success/failure, handling partial-init cleanup safely, and tracking global GnuTLS init/deinit state. Updated sample config defaults to avoid embedded plaintext admin passwords and document hash generation. Commit description made with Copilot.

Replaced the custom SHA256+Base64 password flow with GnuTLS-based PBKDF2-SHA256 records (`scheme$iterations$salt$hash`) and added dedicated generate/verify helpers. FTP login (`PASS`) and `fftp -p` now use the new record format, with secure zeroing of sensitive buffers.

Also improved startup reliability by making TLS initialization return explicit success/failure, handling partial-init cleanup safely, and tracking global GnuTLS init/deinit state. Updated sample config defaults to avoid embedded plaintext admin passwords and document hash generation. Commit description made with Copilot.
@UldisRinkevichs
UldisRinkevichs merged commit 0655c15 into master Sep 20, 2026
2 checks passed
@hfiref0x
hfiref0x deleted the pbkdf2 branch September 20, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants