Re: Re: Problems with PHP calling PGP
| From: | CO Group Support | Date: | Sat, 25 Aug 2001 03:13:59 +0000 |
| Subject: | Re: Re: Problems with PHP calling PGP | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-64388@lists.php.net to get a copy of this message | ||
Hello Richard.
Thanks for the response, but I finally, finally found and fixed the problem.
It turns out that PGP generates output on STDERR, even when you run it in
+batchmode. This extraneous output makes Apache unhappy, for some reason.
So I fixed the problem by inserting a 2>/dev/null into the pgp command to
flush all the STDERR noise down the terlet. Works great now (whew!).
The working code is below, for those who are interested.
Kurt
<script language="php">
/* set up some strings */
$pgppath = "/usr/home/myhome/.pgp";
$ruid = "Recipient Name <recip@isp.com>";
$suid = "Sender Name <sender@isp.com>";
$to = "recip@isp.com";
$subject = "Seekwit Message";
$from = "me@isp.com";
$msg = "This is a vewy, vewy seekwit message.";
putenv("PGPPATH=$pgppath");
/*
* the following code snippets work fine as long as the 2>/dev/null is in
there
* to send the extraneous output
* that PGP generates on STDERR into the bit bucket
*/
/*
* I think the following is the most secure way to do it because it doesn't
include the clear text message
* in the command line, so it should be invisible to people running, for
example, ps -auxxx
*/
$cmd = "/usr/local/bin/pgp -feat +force +batchmode '$ruid' -u '$suid'
2>/dev/null | /usr/bin/mail -s '$subject' $to";
$pp = popen($cmd, "w");
fputs($pp, $msg);
pclose($pp);
/* this one does a straight echo | pgp | mail */
$cmd = "echo '$msg' | /usr/local/bin/pgp -feat +force +batchmode '$ruid' -u
'$suid' 2>/dev/null | /usr/bin/mail -s '$subject' $to";
$cmd;
/* this one does an echo | pg, captures the stdout using backtick, and mails
it using php mail */
$cmd = "echo '$msg' | /usr/local/bin/pgp -feat +force +batchmode '$ruid' -u
'$suid' 2>/dev/null";
$encrypted = $cmd;
$encrypted = "From: $from\n\n" . $encrypted;
mail($to, $subject, "", "$encrypted");
</script>
----- Original Message -----
From: "Richard Lynch" <ceo@l-i-e.com>
To: "CO Group Support" <support@cogroupinc.com>
Cc: <php-general@lists.php.net>
Sent: Friday, August 24, 2001 9:05 PM
Subject: [PHP] Re: Problems with PHP calling PGP
> Note: I am running my PHP script through a program called php-cgiwrap
which
> makes the PHP script execute as me on the server rather than as "nobody".
I
> can't let the script execute as "nobody" because "nobody" doesn't
> have
> permission to run PGP, but I do.
You may want to look at suExec http://apache.org
Try the popen one without the pclose. If that works, upgrade PHP.
Also -- see if you can su to nobody, and run that php-cgiwrap thingie with
this script without Apache being involved.
And, of course, you *ARE* looking at your Apache error_log, right?...
--
WARNING richard@zend.com address is an endangered species -- Use
ceo@l-i-e.com
Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm
Volunteer a little time: http://chatmusic.com/volunteer.htm
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net