# Use sha256 for password file authentication

**URL:** <https://forum.kx.com/t/use-sha256-for-password-file-authentication/12938>\
**Category:** Community Support\
**Tags:** kdb-and-q\
**Created:** [July 17, 2023, 2:47pm UTC](https://forum.kx.com/t/use-sha256-for-password-file-authentication/12938 "2023-07-17T14:47:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jlucid1](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@jlucid1](https://forum.kx.com/u/jlucid1)\
**Post date:** [July 17, 2023, 2:47pm UTC](https://forum.kx.com/t/use-sha256-for-password-file-authentication/12938/1 "2023-07-17T14:47:00Z")

</div>

Currently I am using the -u flag on startup to authenticate users, where the password file contains the sha1 hash of their plain text passwords, the sha1 being generated using -33!.

Is it possible to switch out the sha1 for a sha256 algorithm instead, given that I have a loaded a sha256 function from a shared library?

&nbsp;

&nbsp;

---

<div class="post-metadata">

**Author:** ![davidcrossey1](https://avatars.discourse-cdn.com/v4/letter/d/e68b1a/32.png) [@davidcrossey1](https://forum.kx.com/u/davidcrossey1)\
**Post date:** [July 17, 2023, 3:16pm UTC](https://forum.kx.com/t/use-sha256-for-password-file-authentication/12938/2 "2023-07-17T15:16:00Z")

</div>

I don’t believe sha256 is supported with -u/-U, however you could instead perhaps use .z.pw to carry out custom validation to the effect of:

1. Read your user:sha256 file in the callback when a connection attempt is made
2. Convert the plain text password from the user to sha256
3. Validate the user with 1b (success) or 0b (failure)

References:

- https://code.kx.com/q/releases/ChangesIn2.4/#zpw
- https://code.kx.com/q/ref/dotz/#zpw-validate-user&nbsp;

---

<div class="post-metadata">

**Author:** ![jlucid1](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@jlucid1](https://forum.kx.com/u/jlucid1)\
**Post date:** [July 17, 2023, 6:40pm UTC](https://forum.kx.com/t/use-sha256-for-password-file-authentication/12938/3 "2023-07-17T18:40:00Z")

</div>

Thanks David, yes I was thinking the same, using .z.pw to basically do what I imagine -u is doing 7nder the hood. I just didn’t want to be writing the logic for comparing the users plain text password. Currently with -u, it has the advantage that the logic which does that comparison is inaccessible, so it’s a bit more secure. But if there is no way to overwrite the -33! then defining a .z.pw is the only way to go.
