Re: New Package Proposal Crypt_PGP

From: Date: Wed, 19 Mar 2003 17:20:20 +0000
Subject: Re: New Package Proposal Crypt_PGP
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-14467@lists.php.net to get a copy of this message
> > This is a GNU PGP flaw not a class flaw. > > GPG is prepared to put the private, public keys and the message (when > > you create then ) in a disk file. As much as I see in the documentation > > GPG dont write then to stdout, it writes to 2 files (one for the > > private and other to the public key). > > --output - > wirtes the output to stdout ;) > > and it was just a general remark not really a > if-this-feature-does-not-change-it-should-not-be-in-pear comment and > something you (or the user) should be aware of. > > So you get a +1 from me anyway > Thanks for for +1. My last email was to explain why the class is coded in that way and the limitations the GNUPG program has to allow to script it other (more secure) aproach can be to fork() the script 2 times and create 2 named pipes to pass the keys and the data. But I think that the php's process funtions are still in beta. I think that the class documentation sould have a seccion to help to secure more the temp files creation and deletion Something like:" Don't create the temp files in the default Directory, create one ad-hoc and assign 111 permission to it to deny everybody except root to look out the directory where the second directory containing the tempfiles are created" > chregu ------------------------------------------------- Mail enviado desde el CNBA http://www.cnba.uba.ar/ -----

« previous php.pear.dev (#14467) next »