On Sun, Jan 19, 2020 at 12:26:06PM +0100, Kurt Roeckx wrote: > The only thing that we support currently that makes sense as a > default is -5 (sha256) and -6 (sha512). I suggest you go with -6. I concur, FWIW this is the default password hash for my FreeBSD 12 server, so it is not a Linux-only construct. -- Viktor.