Doc #75707 [NEW]: session.sid_length compatibility note

From: Date: Tue, 19 Dec 2017 18:10:40 +0000
Subject: Doc #75707 [NEW]: session.sid_length compatibility note
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-15296@lists.php.net to get a copy of this message
From: xavier dot leune at gmail dot com Operating system: PHP version: 7.1.12 Package: Documentation problem Bug Type: Documentation Problem Bug description:session.sid_length compatibility note Description: ------------ Hi, We're actually moving to PHP 7.1 and we are trying to add a PHP 7.1 server to our cluster. So we need to make sure that sessions id will be compatible between PHP5 and PHP 7.1. I've read the compatibility note on the parameter session.sid_length but actually I'm not sure the value I should use. Here is the note: Compatibility Note: Use 32 for session.hash_func=0 (MD5) and session.hash_bits_per_character=4, session.hash_func=1 (SHA1) and session.hash_bits_per_character=6. Use 26 for session.hash_func=0 (MD5) and session.hash_bits_per_character=5. Use 22 for session.hash_func=0 (MD5) and session.hash_bits_per_character=6. You must configure INI values to have at least 128 bits in session ID. Do not forget set appropriate value to session.sid_bits_per_character, otherwise you will have weaker session ID. It appears that some information is contradictory. I was trying to update the doc but I'm not sure of what should be written instead. I think it should have only an example for md5 compatibility and one for sha1 compatibility. Can you please tell me what values should be used for this 2 use cases and I'll propose a change in the documentation. Thanks, Xavier. -- Edit bug report at https://bugs.php.net/bug.php?id=75707&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75707&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75707&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75707&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=75707&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=75707&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=75707&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=75707&r=needscript Try newer version: https://bugs.php.net/fix.php?id=75707&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=75707&r=support Expected behavior: https://bugs.php.net/fix.php?id=75707&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=75707&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=75707&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=75707&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75707&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=75707&r=dst IIS Stability: https://bugs.php.net/fix.php?id=75707&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=75707&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=75707&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=75707&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=75707&r=mysqlcfg

« previous php.doc.bugs (#15296) next »