Doc #75707 [Opn->Nab]: session.sid_length compatibility note

From: Date: Mon, 23 Jul 2018 14:44:11 +0000
Subject: Doc #75707 [Opn->Nab]: session.sid_length compatibility note
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-15927@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75707&edit=1 ID: 75707 Updated by: cmb@php.net Reported by: xavier dot leune at gmail dot com Summary: session.sid_length compatibility note -Status: Open +Status: Not a bug Type: Documentation Problem -Package: Documentation problem +Package: Session related PHP Version: 7.1.12 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: MD5 hashes consist of 128bits. The value of session.sid_length *depends* on the value of session.hash_bits_per_character: session.hash_bits_per_character=4 => session.sid_length=32 session.hash_bits_per_character=5 => session.sid_length=26 session.hash_bits_per_character=6 => session.sid_length=22 Analogous for SHA1 hashes. Previous Comments: ------------------------------------------------------------------------ [2017-12-19 18:10:38] xavier dot leune at gmail dot com Description: ------------ Hi, We're actually moving to PHP 7.1 and we are trying to add a PHP 7.1 server to our cluster. So we need to make sure that sessions id will be compatible between PHP5 and PHP 7.1. I've read the compatibility note on the parameter session.sid_length but actually I'm not sure the value I should use. Here is the note: Compatibility Note: Use 32 for session.hash_func=0 (MD5) and session.hash_bits_per_character=4, session.hash_func=1 (SHA1) and session.hash_bits_per_character=6. Use 26 for session.hash_func=0 (MD5) and session.hash_bits_per_character=5. Use 22 for session.hash_func=0 (MD5) and session.hash_bits_per_character=6. You must configure INI values to have at least 128 bits in session ID. Do not forget set appropriate value to session.sid_bits_per_character, otherwise you will have weaker session ID. It appears that some information is contradictory. I was trying to update the doc but I'm not sure of what should be written instead. I think it should have only an example for md5 compatibility and one for sha1 compatibility. Can you please tell me what values should be used for this 2 use cases and I'll propose a change in the documentation. Thanks, Xavier. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75707&edit=1

« previous php.doc.bugs (#15927) next »