Doc #75707 [NEW]: session.sid_length compatibility note
| From: | xavier dot leune at gmail dot com | Date: | Tue, 19 Dec 2017 18:10:40 +0000 |
| Subject: | Doc #75707 [NEW]: session.sid_length compatibility note | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-15296@lists.php.net to get a copy of this message | ||
From: xavier dot leune at gmail dot com
Operating system:
PHP version: 7.1.12
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:session.sid_length compatibility note
Description:
------------
Hi,
We're actually moving to PHP 7.1 and we are trying to add a PHP 7.1
server to our cluster. So we need to make sure that sessions id will be
compatible between PHP5 and PHP 7.1.
I've read the compatibility note on the parameter session.sid_length but
actually I'm not sure the value I should use. Here is the note:
Compatibility Note: Use 32 for session.hash_func=0 (MD5) and
session.hash_bits_per_character=4, session.hash_func=1 (SHA1) and
session.hash_bits_per_character=6. Use 26 for session.hash_func=0 (MD5)
and session.hash_bits_per_character=5. Use 22 for session.hash_func=0
(MD5) and session.hash_bits_per_character=6. You must configure INI
values to have at least 128 bits in session ID. Do not forget set
appropriate value to session.sid_bits_per_character, otherwise you will
have weaker session ID.
It appears that some information is contradictory. I was trying to
update the doc but I'm not sure of what should be written instead. I
think it should have only an example for md5 compatibility and one for
sha1 compatibility.
Can you please tell me what values should be used for this 2 use cases
and I'll propose a change in the documentation.
Thanks,
Xavier.
--
Edit bug report at https://bugs.php.net/bug.php?id=75707&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75707&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75707&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75707&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75707&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75707&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75707&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75707&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75707&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75707&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75707&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75707&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75707&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75707&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75707&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75707&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75707&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75707&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75707&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75707&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75707&r=mysqlcfg