Re: New security extension: scripthash

From: Date: Sat, 02 Dec 2000 22:42:26 +0000
Subject: Re: New security extension: scripthash
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-39862@lists.php.net to get a copy of this message
> At 22:36 2/12/2000, John Sutton wrote: > >Not quite sure what you are asking here! By "any sort of database" I don't > >suppose you mean ndbm as opposed to gdbm... > >Yes, a server has the passwords. The key question is: how can the server > >determine if the request for a particular password is legitimate? This > >extension is an attempt to solve that problem. > > I guess my question was 'how'. SQL databases attempt to do it using a > user/password mechanism (it's true that with gdbm you won't have that kind > of protection), but then, that's the mechanism you're trying to > protect. How does scripthash do it? Each scripthash "client" (e.g. mysqlpassd and phpsuexecd, the supplied examples) has a certain kind of privileged information. The scripthash is the key which unlocks that information. Take a concrete example - mysqlpassd. This is a simple server which has access to a list of mysql passwords. In the implementation we have supplied, this list happens to be held in a gdbm file, but this is irrelevant to the security question. All that matters is that mysqlpassd runs under unix uid X and the file of passwords is owned by X and is not accessible to any other uid. So, the only way to get a password is to connect to the server (through a unix domain socket, or whatever) and satisy the server that you should be given a password. The means to satisfy the server that you should be given a password for a particular user is to present the server with a valid scripthash for that user. A scripthash is an MD5 hash of information about a user (we call this the scripthash user, and currently this is restricted to the unix owner of the php script which generated the scripthash) AND, crucially, a secret. Only a "process" which has access to this secret can possibly generate a valid scripthash. And the only "process" which has access to this secret (apart from mysqlpassd itself, and other scripthash clients) is the internal php function scripthash(). So, a valid scripthash presented to mysqlpassd containing scripthash user "foo" means <<this connection is from an apache daemon running a php script which is owned by unix user "foo">>. So mysqlpassd can safely supply a password to this connection on the assumption that a script which is owned by unix user "foo" was written by unix user "foo" and so is going to make responsible use of this password. I have put in the hooks to allow the scripthash user to be the VirtualHost User rather than, or in addition to, the owner of the script. That's the theory! Question is, is it sound? *************************************************** John Sutton SCL Computer Services URL http://www.scl.co.uk/ Tel. +44 (0) 1239 621021 ***************************************************

« previous php.dev (#39862) next »