Re: Session security
| From: | Stanislav Malyshev | Date: | Tue, 29 May 2007 20:17:45 +0000 |
| Subject: | Re: Session security | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-29895@lists.php.net to get a copy of this message | ||
I'm still unclear on how you validate that the authentication cookie came from the same client machine as the one the application first sent it to, which was the core of my question. The answer seems to be that you can't do it reliably.As far as I understand, no, you can't, unless you have secure external means to establish client identity (like client certificate). -- Stanislav Malyshev, Zend Products Engineer stas@zend.com http://www.zend.com/