Re: unify entropy source for all php related functions
| From: | Yasuo Ohgaki | Date: | Thu, 13 Feb 2014 10:42:01 +0000 |
| Subject: | Re: unify entropy source for all php related functions | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72554@lists.php.net to get a copy of this message | ||
Hi Pierre,
On Thu, Feb 13, 2014 at 6:36 PM, Pierre Joye <pierre.php@gmail.com> wrote:
> session.entropy_file won't be deprecated but will share the same, or can
> share the same source. I can perfectly imagine large set oh hosts using two
> sources, one for session and one for user land usages.
>
> On windows they are not ignored but must be set. We can always add support
> for hardware RNG or servers. A couple of good ones exist but we need to
> test them (stream). We only support the windows crypto api for now.
>
> There will be no hard coded default values but compile time default values
> (as we do it now for other settings). These settings must system settings,
> apps should not be able to change them.
>
> The open issue can be dropped. We are not going to provide that through
> these settings, not now.
>
> Target is 5.6.
>
Updated the RFC to reflect your comment.
I might not understand default INI setting. I removed hard coded default
and made these INIs as INI_PERDIR and build time defined. i.e. Decided by
platform.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net