Binary extensions via PECL
| From: | Marko Karppinen | Date: | Fri, 26 Jul 2002 15:21:17 +0000 |
| Subject: | Binary extensions via PECL | ||
| Groups: | php.dev php.pear.dev | ||
| Request: | Send a blank email to php-dev+get-86243@lists.php.net to get a copy of this message | ||
Hey people,
We had a long discussion with Stig, Jani, Stefan et al about the
infrastructure needed to distribute ready-made binaries of
extensions via PECL. This message contains a summary of our
discussion and some action items at the end. Please participate.
-------
The primary requirement of this project is security. Without
built-in security measures, the PEAR/PECL installer will be a
hazard to our users. Moreover, only a secure tool will have a
chance of making it into Debian, Red Hat or Apple default
installations.
The original idea put forward by Stig was to use GnuPG, but we
concluded that it is too hard a dependency to satisfy. The people
who have most to gain from binary extensions are the ones who
most likely don't have gpg installed.
The lowest common denominator, the software that gives us adequate
security and can be found on a majority of *ix systems is OpenSSL.
It will be the base of the secure distribution mechanism we're
building.
Here's a short description on how OpenSSL would be used to secure
the system.
1. Someone from the PHP Group will be designated the PHP
Certificate Authority. This person will, on a mostly
non-connected system, grant certificates for all
PEAR/PECL package maintainers. He will also maintain
a Certificate Revocation List on www.php.net.
The PHP CA public key will be distributed with
all copies of PHP.
2. Package maintainers will prepare their packages like before.
In addition to the package, they will prepare an S/MIME
message that contains the SHA1 (RFC3174) hash of the
package in question. The maintainers will cryptographically
sign this message and send it to the repository along
with the package.
3. The PEAR/PECL installer will fetch both the package and
the accompanying S/MIME message, verifying that the
signatory has been certified by the PHP CA. The installer
will also check that the signatory has not been placed
on the php.net CRL. Finally, the installer will determine
whether the SHA1 hash in the message matches with the
hash of the downloaded package. If not, the installation
is aborted.
-------
So, here are the action items:
- We need a volunteer for the PHP CA.
- Everyone needs to try and find a gaping whole in the
process described above.
- Dan Kalowsky (kalowsky@php.net) has promised to coordinate
the effort. He will post about the practical roadmap to
our goal. Help him if you can.
- After this change the OpenSSL extension will be a significant
enabler of the PEAR/PECL infrastructure. It should be
on by default (if the host has OpenSSL installed).
- Plans should be formulated on how this will be applied to
the sources distributed by the system. For all intents and
purposes, they are just as insecure as binaries.
Thanks.
mk