diff --git a/admin/index.php b/admin/index.php index 35f511d7d45..55597238c5c 100644 --- a/admin/index.php +++ b/admin/index.php @@ -635,8 +635,9 @@ } - if (empty($CFG->passwordsaltmain)) { - print_box(get_string('upgrade197notice', 'admin')."\n".get_string('upgrade197salt', 'admin')); + if (empty($CFG->passwordsaltmain) || 1==1) { + $path = $CFG->docroot.'/'.str_replace('_utf8', '', current_language()).'/report/security/report_security_check_passwordsaltmain'; + print_box(get_string('upgrade197notice', 'admin')."\n".get_string('upgrade197salt', 'admin', $path)); } if (defined('WARN_DISPLAY_ERRORS_ENABLED')) { diff --git a/admin/report/security/lib.php b/admin/report/security/lib.php index 0591628cbfe..16af87a8d66 100644 --- a/admin/report/security/lib.php +++ b/admin/report/security/lib.php @@ -510,7 +510,8 @@ function report_security_check_passwordsaltmain($detailed=false) { } if ($detailed) { - $result->details = get_string('check_passwordsaltmain_details', 'report_security'); + $docspath = $CFG->docroot.'/'.str_replace('_utf8', '', current_language()).'/report/security/report_security_check_passwordsaltmain'; + $result->details = get_string('check_passwordsaltmain_details', 'report_security', $docspath); } return $result; diff --git a/lang/en_utf8/admin.php b/lang/en_utf8/admin.php index 0796ea836ef..606306744b8 100644 --- a/lang/en_utf8/admin.php +++ b/lang/en_utf8/admin.php @@ -762,8 +762,7 @@ $string['upgrade197notice'] = '
Moodle 1.9.7 contains a number of security fix
As a result some of your settings and permissions relating to backups may have changed.
Please see the Moodle 1.9.7 release notes for full details.
It is strongly recommended that a password salt is set as it greatly reduces the risk of password theft.
To set a password salt add the following to your config.php file.
\$CFG->passwordsaltmain = \'a_very_long_random_string_of_characters#@6&*1\';
-The random string of characters should be a mix of letters, numbers and other characters.
-When changing main salt make sure that you include the old value in config.php, there may be 20 alternative salts. Without the old value in alternative salts list users will not be able to login and will have to use password reset.\$CFG->passwordsaltalt1 = \'previous_main_salt\';
Setting a password salt greatly reduces the risk of password theft.
+To set a password salt, add the following line to your config.php file:
+\$CFG->passwordsaltmain = \'some long random string here with lots of characters\';
+The random string of characters should be a mix of letters, numbers and other characters. A string length of at least 40 characters is recommended.
+Please refer to the password salting documentation if you wish to change the password salt. Once set, do NOT delete your password salt otherwise you will no longer be able to login to your site!
'; $string['check_riskadmin_detailsok'] = 'Please verify the following list of system administrators:
$a'; $string['check_riskadmin_detailswarning'] = 'Please verify the following list of system administrators:
$a->adminsIt is recommended to assign administrator role in system context only. Following users have unsupported admin role assignments:
$a->unsupported'; diff --git a/lib/db/upgrade.php b/lib/db/upgrade.php index 6a3181739d4..d5761bc945d 100644 --- a/lib/db/upgrade.php +++ b/lib/db/upgrade.php @@ -3195,7 +3195,8 @@ function xmldb_main_upgrade($oldversion=0) { $message = get_string('upgrade197notice', 'admin'); if (empty($CFG->passwordmainsalt)) { - $message .= "\n".get_string('upgrade197salt', 'admin'); + $docspath = $CFG->docroot.'/'.str_replace('_utf8', '', current_language()).'/report/security/report_security_check_passwordsaltmain'; + $message .= "\n".get_string('upgrade197salt', 'admin', $docspath); } notify($message, 'notifysuccess'); @@ -3209,7 +3210,8 @@ function xmldb_main_upgrade($oldversion=0) { $messagesubject = get_string('upgrade197noticesubject', 'admin'); $message = addslashes(get_string('upgrade197notice', 'admin')); if (empty($CFG->passwordmainsalt)) { - $message .= "\n".get_string('upgrade197salt', 'admin'); + $docspath = $CFG->docroot.'/'.str_replace('_utf8', '', current_language()).'/report/security/report_security_check_passwordsaltmain'; + $message .= "\n".get_string('upgrade197salt', 'admin', $docspath); } // Force administrators to change password on next login