The dev FAQ should contain information on how to safely (and painlessly) migrate from plain-text/MD5/SHA1 to a more secure algorithm.
https://docs.djangoproject.com/en/dev/topics/auth/passwords/
A list of password hashers, on successful login the user is upgraded to the top password hasher. Makes it very simple to switch to a new scheme or work factor.
hash = CryptContext(
# upgrading from an md5_crypted system
["sha256_crypt", "md5_crypt"],
deprecated=['auto'])
# in auth code
valid, updated = hash.verify_and_update(password, current_hash)
if not valid:
# error out
if updated is not None:
# updated is the new hash to set in database
[0] https://pythonhosted.org/passlib/[1] https://pythonhosted.org/passlib/lib/passlib.context.html?hi...