Doc #65315 [Opn]: session.hash_function always using md5
| From: | nbari at dalmp dot com | Date: | Fri, 26 Jul 2013 09:42:06 +0000 |
| Subject: | Doc #65315 [Opn]: session.hash_function always using md5 | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-10118@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65315&edit=1
ID: 65315
User updated by: nbari at dalmp dot com
Reported by: nbari at dalmp dot com
Summary: session.hash_function always using md5
Status: Open
Type: Documentation Problem
Package: Session related
Operating System: FreeBSD
PHP Version: 5.4.17
Block user comment: N
Private report: N
New Comment:
And what about to check if there is a 'hash' function in the extensions before
using the defaults ?
otherwise users are force to compile in the core the hash extension.
Previous Comments:
------------------------------------------------------------------------
[2013-07-26 00:27:55] yohgaki@php.net
This is expected (designed) behavior.
If there isn't a hash function, session module fallback to default hash function
which is MD5 currently.
I'm not sure if this documented, so I left this as documentation problem.
------------------------------------------------------------------------
[2013-07-23 13:57:43] nbari at dalmp dot com
Description:
------------
session.hash_function not working when having the session and hash extension
compiled out of the core.
ini_set('session.hash_function', 'sha256') returns a session with md5 hash not
sha256
To fix this, php must be compiled using: --enable-hash and --enable-session
Test script:
---------------
<?php
ini_set('session.hash_function', 'sha256');
ini_set('session.hash_bits_per_character', 5);
session_start();
var_dump(session_id());
Expected result:
----------------
string(52) "qcpidhu1jabq225probhkmegnehkrp3fetpdvflumpfbdvo7gis0"
a session hashed with the specified algorithm, in this case 'sha256'
Actual result:
--------------
string(26) "h5rbp62tghln79n92cqicjmce5"
a session hashed with the md5 algo
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65315&edit=1