Deprecate MD5 login method and replace with BCRYPT hash


For many years, Mantis has been using MD5 as the default and "best" hashing algorithm to store users passwords in the database. Since 2.x requires PHP 5.5.9, we can now use the *password_hash()* function, which relies on the modern and safe BCRYPT hashing algorithm for better security.

Additional Information

This basically makes several old issues in the tracker that aimed at replacing MD5 by SHA1/SHA256 obsolete, including #10172, #11250 and possibly others as well.