Doc #63146 [Opn->Csd]: Use /dev/urandom as default random pool dev
| From: | cmb@php.net | Date: | Sun, 14 Jun 2015 21:41:48 +0000 |
| Subject: | Doc #63146 [Opn->Csd]: Use /dev/urandom as default random pool dev | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12429@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=63146&edit=1
ID: 63146
Updated by: cmb@php.net
Reported by: laruence@php.net
Summary: Use /dev/urandom as default random pool dev
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: mcrypt related
Operating System: Linux
PHP Version: 5.4.7
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2015-06-14 21:41:18] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=336958
Log: added note about potential blocking of MCRYPT_DEV_RANDOM (fixes #63146)
------------------------------------------------------------------------
[2012-09-25 02:43:43] laruence@php.net
IMO, most users are using mcrypt as a password generator,
however, I do agree, we can solve this with a well documentation.
change to doc bug
------------------------------------------------------------------------
[2012-09-24 07:32:47] pajoye@php.net
hi!
mcrypt extensions is about crypto safe usage. /dev/random is crypto safe,
/dev/urandom is only good enough for password generations and the like.
However I totally agree that we should document the possible blocking behavior. It
is already mentioned in the notes, but better if we have a warning/notice on that
page.
------------------------------------------------------------------------
[2012-09-24 04:45:44] aharvey@php.net
Given it's a cryptographic function, I think we should continue to use /dev/random, but we
could document more clearly that the default behaviour may block until more entropy is available.
------------------------------------------------------------------------
[2012-09-24 04:27:26] laruence@php.net
Description:
------------
Hey, mcrypt_create_iv use /dev/random as the default random dev, this will cause
some unexpected issues for new users.
see:
"
nils at nm dot cx 19-Jun-2012 12:26
If you use /dev/random you need a well filled entropy pool or the application will
block until enough good entropy comes available
"
http://us.php.net/manual/en/function.mcrypt-create-iv.php
Test script:
---------------
none
Expected result:
----------------
none
Actual result:
--------------
none
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=63146&edit=1