authentication and sessions
| From: | Dean Hall | Date: | Fri, 18 Aug 2000 09:45:49 +0000 |
| Subject: | authentication and sessions | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-12449@lists.php.net to get a copy of this message | ||
I'm trying to come up with a secure system to authenticate users for a
session using MySQL (and possibly the /etc/shadow password file) and PHP
sessions (PHP4).
First of all, has anyone come up with a decent scheme for authentication? --
that is, I want the user to fill out a form (NOT HTTP authentication) and
have the password transmitted encrypted -- not in plaintext. (I have an MD5
function in JavaScript that really works, so the password could be hashed on
the client.) Plus, I want to retain knowledge that the user has been
authenticated with session variables (that is, either cookies or GET/POST
variables).
The problem is, I don't want these session variables to be spoofable. In
other words, I don't want someone to be able to reproduce a cookie exactly
and be able to log in as that user. Does the SESSID variable take care of
this? Should I store a variable hashed with a private server key and store
it in the cookie? Should I reauthenticate the user's stuff every time they
visit (from the session variables)?
I could do all authentication over SSL, but are cookies stored encrypted as
well when got from a secure site?
Second of all, are there any utilities for changing a user's password in the
/etc/shadow file? I would like users to be able to change their shell
account passwords and keep it in sync with the database password. I realize
I'd have to run such a utility as setuid root.
I guess I'm looking for someone who has actually done this in a
cryptographically secure manner. Anyone?
Dean.
Administrator and Webmaster, Apt7.com Web Services
http://www.apt7.com