2017-11-17 10:35 GMT+01:00 Aleksey Qwerty <russian.qwe...@gmail.com>: > Hi Clément, > >> This is not very risky, as the token is sent in the mail. We crypt it >> only to not display the raw PHP session in the mail. The token crypt >> is mandatory only if you use the reset by SMS feature. > > Thank you for clarification, but can we try to fix the issue with crypto > library? > Do we have any newer version of > /usr/share/self-service-password/lib/vendor/defuse-crypto.phar or something?
I don't know, you can open an issue on this subject. The problem can be with the PHP version from CentOS 6. You could try to install SSP on CentOS 7. Clément. _______________________________________________ ltb-users mailing list ltb-users@lists.ltb-project.org https://lists.ltb-project.org/cgi-bin/mailman/listinfo/ltb-users