Re: New Package Proposal Crypt_PGP
| From: | DESC) | Date: | Wed, 19 Mar 2003 17:20:20 +0000 |
| Subject: | Re: New Package Proposal Crypt_PGP | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-14467@lists.php.net to get a copy of this message | ||
> > This is a GNU PGP flaw not a class flaw.
> > GPG is prepared to put the private, public keys and the message (when
> > you create then ) in a disk file. As much as I see in the documentation
> > GPG dont write then to stdout, it writes to 2 files (one for the
> > private and other to the public key).
>
> --output -
> wirtes the output to stdout ;)
>
> and it was just a general remark not really a
> if-this-feature-does-not-change-it-should-not-be-in-pear comment and
> something you (or the user) should be aware of.
>
> So you get a +1 from me anyway
>
Thanks for for +1.
My last email was to explain why the class is coded in that way and the
limitations the GNUPG program has to allow to script it
other (more secure) aproach can be to fork() the script 2 times and create 2
named pipes to pass the keys and the data. But I think that the php's process
funtions are still in beta.
I think that the class documentation sould have a seccion to help
to secure more the temp files creation and deletion
Something like:"
Don't create the temp files in the default Directory, create one ad-hoc and
assign 111 permission to it to deny everybody except root to look out the
directory where the second directory containing the tempfiles are created"
> chregu
-------------------------------------------------
Mail enviado desde el CNBA
http://www.cnba.uba.ar/
-----