Re: Make mcrypt_create_iv() an alias and move the code into /ext/standard
| From: | Pierre Joye | Date: | Fri, 07 Feb 2014 07:15:23 +0000 |
| Subject: | Re: Make mcrypt_create_iv() an alias and move the code into /ext/standard | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72368@lists.php.net to get a copy of this message | ||
On Fri, Feb 7, 2014 at 8:10 AM, Tjerk Meesters <tjerk.meesters@gmail.com> wrote:
> Hi Thomas,
>
> On Fri, Feb 7, 2014 at 3:05 PM, Thomas Hruska <thruska@cubiclesoft.com>wrote:
>
>> mcrypt_create_iv() is the cleanest access to a universal system-level
>> primitive that supports both /dev/urandom and php_win32_get_random_bytes()
>> under the hood. Unfortunately, it resides in /ext/mcrypt and the mcrypt
>> extension isn't always enabled/available (nor should it be). At any rate,
>> it is quite odd that the function php_win32_get_random_bytes() is compiled
>> into the core of PHP by default under Windows but there's currently no way
>> to get at it except through an extension. There's good code in
>> mcrypt_create_iv() that is significantly useful outside of the rest of that
>> extension and it isn't actually dependent upon libmcrypt for proper
>> operation.
>>
>
> We already have something similar to that in password.c:
>
> http://lxr.php.net/xref/PHP_5_6/ext/standard/password.c#111
>
> It shouldn't be hard to turn this into an API function so that other code
> written against php can use it for their own purposes.
While reading this code portion, I wonder if anyone has tested it on
system where there is no urandom available but other names. I think it
should use the entropy source ini setting instead of hard coded
urandom. Thoughts?
Cheers,
--
Pierre
@pierrejoye | http://www.libgd.org