Re: Sessions not propagated through different hosts - *Urgent!*
| From: | Monte Ohrt | Date: | Thu, 13 Jul 2000 21:43:57 +0000 |
| Subject: | Re: Sessions not propagated through different hosts - *Urgent!* | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-6555@lists.php.net to get a copy of this message | ||
One more thought about this that may be easier than my first idea:
Encrypt the session file with a key known only to the two servers.
Then URL encode the encrypted data and pass it either in a form
or through the URL to the next server. This server urldecodes the
data and decrypts it with the private key, and puts the session
data in the session file directory. Of course, this needs to happen
before calling session_start()
Monte
Christopher Thompson wrote:
>
> I did not see a response to this, and am going to come up on this problem
> soon as well. Here are some of my thoughts:
>
> - I assume that if both standard and secure servers are on the same
> machine then setting session.cookie_domain or one of its related settings
> will allow the session library to resolve the user across the two. I am
> guessing that you could do that across two machines in the same Class C.
>
> - The session information must be physically shared between all servers,
> either with the same path, NFS mount, or in a commonly accessed database.
>
> - If the machines are completely seperate, then when moving from one
> machine to the other, the session ID and data would have to be passed back
> and forth. The session ID would be easy to pass. The serialized data could
> be passed via a form or in the URL, but this would cause security problems
> unless it was encrypted.
>
> Has anyone implemented the simplest case: separate HTTP and SSL servers
> running on the same machine, maintaining the session across the two? I
> would be interested in information about that.
>
> > -----Original Message-----
> > From: Pedro Fonseca [mailto:pedro.fonseca@iscte.pt]
> > Sent: Thursday, July 13, 2000 5:07 AM
> > To: php-general@lists.php.net
> > Subject: [PHP] Sessions not propagated through different hosts -
> > *Urgent!*
> >
> >
> > Hi,
> >
> > I posted a message here yesterday, regarding a problem with a
> > site we are
> > developing. I will briefly describe the problem again:
> >
> > We are using two different (physical) computers, each with its
> > own apache
> > web server (and consequently each with its own php module). One
> > of them is
> > SSL secured and the other is not. All the php files that need
> > to be secured
> > (like client registration, contracts, personal information,
> > etc) are on the
> > secured server; all the "normal" files (index.php, product
> > catalogs, etc)
> > that need not to be secured are on the normal server.
> >
> > When someone arrives at the site, index.php (that is on the non secured
> > server) is parsed and a session is created. After a user logs
> > himself in,
> > he/she can access the secured files (i.e. can access he/she's personal
> > information, can buy images, etc). So, when a user (after logging in)
> > clicks the first file that is on the secured server, the login form
> > reapears like the user never got to loggin in the first place.
> > So we have a
> > session that's created when a user arrives at the site and one
> > other when
> > he accesses the secured files.
> >
> > We tried to make both servers' session_save_path to /tmp of the
> > non-secured
> > server but this did not work! Thus the problem is not derived
> > from having
> > two different session_save_path (what about
> > session.cookie_domain - what is
> > it for?). It seems that this happens because we are using two physical
> > different locations for the files, i.e. two different hosts. Wasn't this
> > not supposed to happen?, I mean weren't the files on the secured server
> > supposed to continue the session already created by the "normal" files?
> >
> > Please, this is a very urgent problem we need to solve! Any
> > help, ideas or
> > any contribution is much appreciated (thanks Chris Broussard
> > and Jon Parise
> > for yesterday's tips, but we haven't solved the problem yet!)!
> > If any PHP
> > language developers are reading this we would be very thankfull for your
> > attention!
> >
> > Best regards,
> >
> > Pedro Fonseca
> >
> > /**
> > * pedro.fonseca@iscte.pt
> > * http://students.iscte.pt/~a17253/aminhapagina/
> > * Mobile: 96.459.835.7
> > *
> > **/
> >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-general-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
> >
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
Monte Ohrt <monte@ispi.net>
http://www.ispi.net/