Re: New security extension: scripthash

From: Date: Sat, 09 Dec 2000 10:25:47 +0000
Subject: Re: New security extension: scripthash
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-40641@lists.php.net to get a copy of this message
> > > protect. How does scripthash do it? > > Maybe I'm just slow, but I didn't quite get it. > Apache generates a random secret at startup, right? Yes. (And in v0.3 coming soon, optionally the secret is regenerated every X seconds, just for those who are super paranoid. ;-) > So the different apps (e.g. mysqlpassd) needs to know this secret > to validate the requests, right? Yes. > So how is the secret shared between the apps and apache? > And what prevents a third party application from doing the exact same > thing to get the secret? It's stored in a shared memory segment which is owned by root (or whoever starts up apache) and has mode 600. So, only processes running as root can read it EXCEPT for the apache children themselves. They can read it even though they are running as uid nobody because the attach of the memory segment survives the fork. This is the key to the whole thing. > Some detailed issues though: > * mysqlpasswd has nothing to do with mysql - maybe a different name > would be better? > * Could mysqlpassdbm replace the password file instead of changing it? > Then it didn't have to stop mysqlpasswd while updating. It would be > enough to HUP mysqlpasswd after updating the file - or even better, > the deamon can stat the file and discovere it is updated itself. > (or maybe even better, mysqlpasswd can compile the dbm file itself > from a plaintext file, every time the file is updated - like sendmail > does for it's aliases files). > * the spec file should put the scripthash files in a seperate rpm > from php itself - like the redhat rpm does with all the modules. All your comments are perfectly valid but as you say yourself they are matters of detail. I'm not inclined to put much more effort into it until the "big guns" pass judgement on the basic security issues: 1) how safe is the secret? 2) how big do the secret and the random string need to be? Once these matters are resolved, I'm hoping that the scripthash extension itself might find its way into the base distribution, and the associated apps will become PEAR "widgets"? *************************************************** John Sutton SCL Computer Services URL http://www.scl.co.uk/ Tel. +44 (0) 1239 621021 ***************************************************

« previous php.dev (#40641) next »