Req #72744 [Com]: https://wiki.php.net/rfc/session-id-without-hashing

From: Date: Thu, 04 Aug 2016 05:22:30 +0000
Subject: Req #72744 [Com]: https://wiki.php.net/rfc/session-id-without-hashing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202904@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72744&edit=1 ID: 72744 Comment by: spam2 at rhsoft dot net Reported by: spam2 at rhsoft dot net Summary: https://wiki.php.net/rfc/session-id-without-hashing Status: Wont fix Type: Feature/Change Request Package: Session related PHP Version: Next Minor Version Assigned To: yohgaki Block user comment: N Private report: N New Comment: Yes i mean that settings, hence the are part of my initial report which is about *just read them* to provide a backward compatible behavior instead remove them and introduce new ini settings Previous Comments: ------------------------------------------------------------------------ [2016-08-04 05:16:58] spam2 at rhsoft dot net Come on LOUNGE_ID *is* the session ID which becomes obvious when you even comment the line before which forbids the default PHPSESSID and as if you say it's about length and chars - guess what the Regex of the third rule does If someone would have changed the silly default from md5 to sha1 many years ago we would just talk about a bc compatible 160 bit default ------------------------------------------------------------------------ [2016-08-04 02:39:51] yohgaki@php.net I guess you mean - session.hash_function=1 (sha1) - session.hash_bits_per_chars=6 yields session ID with length=32 chars. To achieve the same result, users would set - session.sid_length=32 - session.sid_bits_per_chars=6 I'll document them. ------------------------------------------------------------------------ [2016-08-04 02:27:51] yohgaki@php.net I could be wrong, but anyway SecRule REQUEST_COOKIES_NAMES|ARGS_NAMES "(^PHPSESSID$|JSESSIONID$|ASPSESSIONID$|ASP\.NET_SessionId$)" "id:'133',phase:2,capture,logdata:'%{TX.0}',block,msg:'Invalid SessionID name not allowed'" This seems to be a Cookie name match. Irrelevant as default session name is not changed. SecRule ARGS_NAMES "(^LOUNGE_ID$|PANEL_ID$)""id:'134',phase:2,capture,logdata:'%{TX.0}',block,msg:'LOUNGE_ID not allowed via GET or POST'" This seems nothing to do with PHP session ID. SecRule REQUEST_COOKIES:LOUNGE_ID|REQUEST_COOKIES:PANEL_ID "!@rx ^[-a-z0-9,]{27}$" "id:'135',phase:2,logdata:'%{matched_var}',t:urlDecodeUni,t:lowercase,block,msg:'Unexpected value for LOUNGE_ID'" This seems nothing to do with PHP session ID. What important here is - Session ID length - Chars used by session ID session.sid_lengh = 32 session.sid_bits_per_character = 4 or 5 6 is a little intrusive as it contains non alphanum char. 5 could be BC if something validates session value as hex string. For users using non default sha1 or sha2 hashes, they have to adjust INI by their own anyway. Therefore, there is no BC. ------------------------------------------------------------------------ [2016-08-03 16:01:19] cmb@php.net Assigned to RFC author. ------------------------------------------------------------------------ [2016-08-03 14:09:51] spam2 at rhsoft dot net Description: ------------ > Compatible defaults: session.sid_length=32, session.sid_bits_per_character=4 > (128 bits session ID. No BC break) that is not true in case of smarter sysadmins which swicthed away from the MD5 default years ago and hence in case the sesstings are present in "php.ini" it should change it's default behavior to *really* be compatible ____________________________ session.entropy_length = 32 session.hash_function = 1 session.hash_bits_per_character = 6 SecRule REQUEST_COOKIES_NAMES|ARGS_NAMES "(^PHPSESSID$|JSESSIONID$|ASPSESSIONID$|ASP\.NET_SessionId$)" "id:'133',phase:2,capture,logdata:'%{TX.0}',block,msg:'Invalid SessionID name not allowed'" SecRule ARGS_NAMES "(^LOUNGE_ID$|PANEL_ID$)""id:'134',phase:2,capture,logdata:'%{TX.0}',block,msg:'LOUNGE_ID not allowed via GET or POST'" SecRule REQUEST_COOKIES:LOUNGE_ID|REQUEST_COOKIES:PANEL_ID "!@rx ^[-a-z0-9,]{27}$" "id:'135',phase:2,logdata:'%{matched_var}',t:urlDecodeUni,t:lowercase,block,msg:'Unexpected value for LOUNGE_ID'" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72744&edit=1

« previous php.bugs (#202904) next »