unify entropy source for all php related functions
| From: | Pierre Joye | Date: | Fri, 07 Feb 2014 11:25:45 +0000 |
| Subject: | unify entropy source for all php related functions | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-72374@lists.php.net to get a copy of this message | ||
hi,
There are a lot of additions and discussions about entropy source and
(P)RNG lately.
PHP already has a ini setting to define a strong entropy source for
the session module, which defaults to urandom or arandom.
I would like to create two settings to unify the entropy source
accross php functions. That includes mcrypt, new password APIs,
session, LCG, etc.
Something along this line:
random.entropy_strong_source (/dev/(u|a)random etc.)
random.entropy_crypto_source (/dev/random etc.)
I am not willing to propose new RNG functions or extensions for 5.6 as
we have way too little time to actually discuss its design and APIs.
However having these settings unified and documented would be a good
step forward already.
Thoughts?
Cheers,
--
Pierre
@pierrejoye | http://www.libgd.org