RE: [PHP] Sessions not propagated through different hosts - *Urgent!*
| From: | Christopher Thompson | Date: | Thu, 13 Jul 2000 21:10:07 +0000 |
| Subject: | RE: [PHP] Sessions not propagated through different hosts - *Urgent!* | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-6547@lists.php.net to get a copy of this message | ||
I did not see a response to this, and am going to come up on this problem
soon as well. Here are some of my thoughts:
- I assume that if both standard and secure servers are on the same
machine then setting session.cookie_domain or one of its related settings
will allow the session library to resolve the user across the two. I am
guessing that you could do that across two machines in the same Class C.
- The session information must be physically shared between all servers,
either with the same path, NFS mount, or in a commonly accessed database.
- If the machines are completely seperate, then when moving from one
machine to the other, the session ID and data would have to be passed back
and forth. The session ID would be easy to pass. The serialized data could
be passed via a form or in the URL, but this would cause security problems
unless it was encrypted.
Has anyone implemented the simplest case: separate HTTP and SSL servers
running on the same machine, maintaining the session across the two? I
would be interested in information about that.
> -----Original Message-----
> From: Pedro Fonseca [mailto:pedro.fonseca@iscte.pt]
> Sent: Thursday, July 13, 2000 5:07 AM
> To: php-general@lists.php.net
> Subject: [PHP] Sessions not propagated through different hosts -
> *Urgent!*
>
>
> Hi,
>
> I posted a message here yesterday, regarding a problem with a
> site we are
> developing. I will briefly describe the problem again:
>
> We are using two different (physical) computers, each with its
> own apache
> web server (and consequently each with its own php module). One
> of them is
> SSL secured and the other is not. All the php files that need
> to be secured
> (like client registration, contracts, personal information,
> etc) are on the
> secured server; all the "normal" files (index.php, product
> catalogs, etc)
> that need not to be secured are on the normal server.
>
> When someone arrives at the site, index.php (that is on the non secured
> server) is parsed and a session is created. After a user logs
> himself in,
> he/she can access the secured files (i.e. can access he/she's personal
> information, can buy images, etc). So, when a user (after logging in)
> clicks the first file that is on the secured server, the login form
> reapears like the user never got to loggin in the first place.
> So we have a
> session that's created when a user arrives at the site and one
> other when
> he accesses the secured files.
>
> We tried to make both servers' session_save_path to /tmp of the
> non-secured
> server but this did not work! Thus the problem is not derived
> from having
> two different session_save_path (what about
> session.cookie_domain - what is
> it for?). It seems that this happens because we are using two physical
> different locations for the files, i.e. two different hosts. Wasn't this
> not supposed to happen?, I mean weren't the files on the secured server
> supposed to continue the session already created by the "normal" files?
>
> Please, this is a very urgent problem we need to solve! Any
> help, ideas or
> any contribution is much appreciated (thanks Chris Broussard
> and Jon Parise
> for yesterday's tips, but we haven't solved the problem yet!)!
> If any PHP
> language developers are reading this we would be very thankfull for your
> attention!
>
> Best regards,
>
> Pedro Fonseca
>
> /**
> * pedro.fonseca@iscte.pt
> * http://students.iscte.pt/~a17253/aminhapagina/
> * Mobile: 96.459.835.7
> *
> **/
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>