Re: Auth feature

From: Date: Sun, 06 Apr 2003 04:09:38 +0000
Subject: Re: Auth feature
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-14933@lists.php.net to get a copy of this message
The algorithm sound good -except I would assume the md5 would be of username:{encrypted password}:challenge as most normal password storage mechanisms store passwords encrypted by default. - so you would not be able to get the cleartext password.. -- although it is usefull to be able to retreive the original password (for things like webmail etc.) - Or was this the idea.. have you got a simple api example? Regards Alan Yavor Shahpasov wrote:
http://www.sanisoft.com/phplib/manual/auth_Response.php i was going other this out of curiosity, it seems phplib supports challenge responce. I think it would be neat to have this in PEAR auth, it would only work if the password can be retrieved from the backend so some backends could not implemend this but I think it should be doable for DB and File/Passwd from phplib docs Example_Challenge_Auth includes crloginform.ihtml. It also requires that the file md5.js is present in the document root directory of your web server. That file contains an implementation of the MD5 message digest algorithm done by Henri Torgemane. The basic idea behind this authentication scheme is simple: $auth->auth_loginform() creates a challenge value which is incorporated into this form. When the user tries to submit the form, MD5("username:password:challenge") is calculated and filled into the reply field. The password field is erased. The server can calculate the expected reply from the username received, the password in the database and the challenge, which it knows. It can compare the expected reply to the actual reply value. If they match, the user is authenticated. What do you think, I could probably start working on this, will it be accepted martin? Yavor
-- Can you help out? Need Consulting Services or Know of a Job? http://www.akbkhome.com

« previous php.pear.dev (#14933) next »