Doc #75707 [Opn->Nab]: session.sid_length compatibility note
| From: | cmb@php.net | Date: | Mon, 23 Jul 2018 14:44:11 +0000 |
| Subject: | Doc #75707 [Opn->Nab]: session.sid_length compatibility note | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-15927@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75707&edit=1
ID: 75707
Updated by: cmb@php.net
Reported by: xavier dot leune at gmail dot com
Summary: session.sid_length compatibility note
-Status: Open
+Status: Not a bug
Type: Documentation Problem
-Package: Documentation problem
+Package: Session related
PHP Version: 7.1.12
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
MD5 hashes consist of 128bits. The value of session.sid_length
*depends* on the value of session.hash_bits_per_character:
session.hash_bits_per_character=4 => session.sid_length=32
session.hash_bits_per_character=5 => session.sid_length=26
session.hash_bits_per_character=6 => session.sid_length=22
Analogous for SHA1 hashes.
Previous Comments:
------------------------------------------------------------------------
[2017-12-19 18:10:38] xavier dot leune at gmail dot com
Description:
------------
Hi,
We're actually moving to PHP 7.1 and we are trying to add a PHP 7.1 server to our cluster. So
we need to make sure that sessions id will be compatible between PHP5 and PHP 7.1.
I've read the compatibility note on the parameter session.sid_length but actually I'm not
sure the value I should use. Here is the note:
Compatibility Note: Use 32 for session.hash_func=0 (MD5) and session.hash_bits_per_character=4,
session.hash_func=1 (SHA1) and session.hash_bits_per_character=6. Use 26 for session.hash_func=0
(MD5) and session.hash_bits_per_character=5. Use 22 for session.hash_func=0 (MD5) and
session.hash_bits_per_character=6. You must configure INI values to have at least 128 bits in
session ID. Do not forget set appropriate value to session.sid_bits_per_character, otherwise you
will have weaker session ID.
It appears that some information is contradictory. I was trying to update the doc but I'm not
sure of what should be written instead. I think it should have only an example for md5 compatibility
and one for sha1 compatibility.
Can you please tell me what values should be used for this 2 use cases and I'll propose a
change in the documentation.
Thanks,
Xavier.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75707&edit=1