Binary extensions via PECL

From: Date: Fri, 26 Jul 2002 15:21:17 +0000
Subject: Binary extensions via PECL
Groups: php.dev php.pear.dev 
Request: Send a blank email to php-dev+get-86243@lists.php.net to get a copy of this message
Hey people, We had a long discussion with Stig, Jani, Stefan et al about the infrastructure needed to distribute ready-made binaries of extensions via PECL. This message contains a summary of our discussion and some action items at the end. Please participate. ------- The primary requirement of this project is security. Without built-in security measures, the PEAR/PECL installer will be a hazard to our users. Moreover, only a secure tool will have a chance of making it into Debian, Red Hat or Apple default installations. The original idea put forward by Stig was to use GnuPG, but we concluded that it is too hard a dependency to satisfy. The people who have most to gain from binary extensions are the ones who most likely don't have gpg installed. The lowest common denominator, the software that gives us adequate security and can be found on a majority of *ix systems is OpenSSL. It will be the base of the secure distribution mechanism we're building. Here's a short description on how OpenSSL would be used to secure the system. 1. Someone from the PHP Group will be designated the PHP Certificate Authority. This person will, on a mostly non-connected system, grant certificates for all PEAR/PECL package maintainers. He will also maintain a Certificate Revocation List on www.php.net. The PHP CA public key will be distributed with all copies of PHP. 2. Package maintainers will prepare their packages like before. In addition to the package, they will prepare an S/MIME message that contains the SHA1 (RFC3174) hash of the package in question. The maintainers will cryptographically sign this message and send it to the repository along with the package. 3. The PEAR/PECL installer will fetch both the package and the accompanying S/MIME message, verifying that the signatory has been certified by the PHP CA. The installer will also check that the signatory has not been placed on the php.net CRL. Finally, the installer will determine whether the SHA1 hash in the message matches with the hash of the downloaded package. If not, the installation is aborted. ------- So, here are the action items: - We need a volunteer for the PHP CA. - Everyone needs to try and find a gaping whole in the process described above. - Dan Kalowsky (kalowsky@php.net) has promised to coordinate the effort. He will post about the practical roadmap to our goal. Help him if you can. - After this change the OpenSSL extension will be a significant enabler of the PEAR/PECL infrastructure. It should be on by default (if the host has OpenSSL installed). - Plans should be formulated on how this will be applied to the sources distributed by the system. For all intents and purposes, they are just as insecure as binaries. Thanks. mk

« previous php.dev (#86243) next »