Surely, welcoming obvious improvements that will save some other zope developer from re-implementing a secure /etc/passwd
equivalent is desirable.

I agreed. I'll apply slightly modified version of the patch with fixed-length salt if you don't object.

Python 2.5 has hashlib which supports sha224, sha256 and so forth.
I may look into adding support for those hashes to password
when zope has been updated for 2.5.

I think in this case it will make sense to move the module into self contained package for example or even zope.password.

