authentication and sessions

From: Date: Fri, 18 Aug 2000 09:45:49 +0000
Subject: authentication and sessions
Groups: php.general 
Request: Send a blank email to php-general+get-12449@lists.php.net to get a copy of this message
I'm trying to come up with a secure system to authenticate users for a session using MySQL (and possibly the /etc/shadow password file) and PHP sessions (PHP4). First of all, has anyone come up with a decent scheme for authentication? -- that is, I want the user to fill out a form (NOT HTTP authentication) and have the password transmitted encrypted -- not in plaintext. (I have an MD5 function in JavaScript that really works, so the password could be hashed on the client.) Plus, I want to retain knowledge that the user has been authenticated with session variables (that is, either cookies or GET/POST variables). The problem is, I don't want these session variables to be spoofable. In other words, I don't want someone to be able to reproduce a cookie exactly and be able to log in as that user. Does the SESSID variable take care of this? Should I store a variable hashed with a private server key and store it in the cookie? Should I reauthenticate the user's stuff every time they visit (from the session variables)? I could do all authentication over SSL, but are cookies stored encrypted as well when got from a secure site? Second of all, are there any utilities for changing a user's password in the /etc/shadow file? I would like users to be able to change their shell account passwords and keep it in sync with the database password. I realize I'd have to run such a utility as setuid root. I guess I'm looking for someone who has actually done this in a cryptographically secure manner. Anyone? Dean. Administrator and Webmaster, Apt7.com Web Services http://www.apt7.com

« previous php.general (#12449) next »