Re: Make mcrypt_create_iv() an alias and move the code into /ext/standard

From: Date: Fri, 07 Feb 2014 07:15:23 +0000
Subject: Re: Make mcrypt_create_iv() an alias and move the code into /ext/standard
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-72368@lists.php.net to get a copy of this message
On Fri, Feb 7, 2014 at 8:10 AM, Tjerk Meesters <tjerk.meesters@gmail.com> wrote: > Hi Thomas, > > On Fri, Feb 7, 2014 at 3:05 PM, Thomas Hruska <thruska@cubiclesoft.com>wrote: > >> mcrypt_create_iv() is the cleanest access to a universal system-level >> primitive that supports both /dev/urandom and php_win32_get_random_bytes() >> under the hood. Unfortunately, it resides in /ext/mcrypt and the mcrypt >> extension isn't always enabled/available (nor should it be). At any rate, >> it is quite odd that the function php_win32_get_random_bytes() is compiled >> into the core of PHP by default under Windows but there's currently no way >> to get at it except through an extension. There's good code in >> mcrypt_create_iv() that is significantly useful outside of the rest of that >> extension and it isn't actually dependent upon libmcrypt for proper >> operation. >> > > We already have something similar to that in password.c: > > http://lxr.php.net/xref/PHP_5_6/ext/standard/password.c#111 > > It shouldn't be hard to turn this into an API function so that other code > written against php can use it for their own purposes. While reading this code portion, I wonder if anyone has tested it on system where there is no urandom available but other names. I think it should use the entropy source ini setting instead of hard coded urandom. Thoughts? Cheers, -- Pierre @pierrejoye | http://www.libgd.org

« previous php.internals (#72368) next »