note 93946 added to book.openssl
| From: | Anonymous at osu1 dot php dot net | Date: | Thu, 08 Oct 2009 00:28:26 +0000 |
| Subject: | note 93946 added to book.openssl | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-161494@lists.php.net to get a copy of this message | ||
OpenSSL creates asynchronous key pairs, however I wanted to have the private key something that was
human-memorizable. With the standard keys generated, this is not possible. How I achieved it was to
use two types of encryption.
After generating a key pair with OpenSSL, the public key can be stored in plain text format. I then
encrypted the private key itself using regular mcrypt with the human-memorizable key of my choice
and converted it to ACSII using urlencode(). Then to get the private key back, I just decrypted it
with mcrypt. This way I could store the encrypted private key on the server without worrying about
having things stored unencrypted.
Of course, this will only be as good as your human-memorizable key is and can potentially reduce the
security of your script if you choose something simple or don't use salts.
----
Server IP: 92.48.74.199
Probable Submitter: 190.241.39.11
----
Manual Page -- http://www.php.net/manual/en/book.openssl.php
Edit -- https://master.php.net/note/edit/93946
Del: integrated -- https://master.php.net/note/delete/93946/integrated
Del: useless -- https://master.php.net/note/delete/93946/useless
Del: bad code -- https://master.php.net/note/delete/93946/bad+code
Del: spam -- https://master.php.net/note/delete/93946/spam
Del: non-english -- https://master.php.net/note/delete/93946/non-english
Del: in docs -- https://master.php.net/note/delete/93946/in+docs
Del: other reasons-- https://master.php.net/note/delete/93946
Reject -- https://master.php.net/note/reject/93946
Search -- https://master.php.net/manage/user-notes.php