Re: Auth Challenge Responce
| From: | Yavor Shahpasov | Date: | Tue, 27 May 2003 19:45:14 +0000 |
| Subject: | Re: Auth Challenge Responce | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-16753@lists.php.net to get a copy of this message | ||
Basically I nicked your js code :)
Anyhow, this is just a proof of consept, am waiting for some approval on
this
can you explain this about the chapid
> just two short notes:
> - you should always inlcude the chapid into the md5-hash, even it's always
> 1, because otherwise you are breaking the RFC
> - maybe we can find a way for preparing the auth-class for different
> chap-methods (ms-chapv1 and v2), this should allow us later easier
> implement these.
My general idea was to have a chap template parameter in a string with all
possible vars which would have any significance
ex: $chaptpl = "%chapid% %challenge% %responce%";
where the values in %% would be replaced with their values, this would be
implemented both in the js functions and in the php code, allowing to change
the way the responce is calculated. You might want to give a brief intro to
ms-chapv1 and v2 maybe am missing something.
Yavor
----- Original Message -----
From: "Michael Bretterklieber" <mbretter@jawa.at>
To: "Yavor Shahpasov" <yavo@siava.org>
Cc: <pear-dev@lists.php.net>
Sent: Tuesday, May 27, 2003 9:43 PM
Subject: Re: [PEAR-DEV] Auth Challenge Responce
> Hi,
>
> On Sun, 25 May 2003, Yavor Shahpasov wrote:
> > A while back I asked about this in the list, whether it would be
feasible to add such a feature in Auth. I have implemented a proof of
consept modification of it. I know it has taken me a while to do it you can
easily blame my lazines impossible deadlines at work, final, the fact I got
married this month or str_replace('%my_excuse%', generateRandomExcuse(),
'this email'). any how here is a list of things done. Is is a draft by no
means it is meant to be the complete thing !!!
> >
> > changes made to auth include
> > Auth.php
> > *added a Auth::setUseChap(); method, which enable challenge responce
(missing is detection of java script capability on the browser, if not this
should throw a warning and use the standard auth features)
> > * added an importJS method, this basically includes some java script
files it is called by the drawLogin
> > +- changed the drawLogin method, if chap is enabled it uses the java
script to change the password to the challenge responce, it allso passes the
secret as a hiddent field
> > * added getChallenge method, this return the server to be used currently
it just returns the session id but it could be easily changed, everything
uses this method to get the challeneg secret
> >
> > Container.php
> > *added a verifyChap method, similar to
> >
> > Container/DB.php
> > *added a fetchChapData, same as fetchLoginData but calls virifyChap
instead of verifyPasword, it also passes different parameters to the
virifyChap method than verify password ($challenge,
$challengeresponce,$entry[$this->options['passwordcol']],$chaptemplate)
> >
> >
> > General structure
> > if chap is enable, some java script files are included
> > oncklick event of the submit button replaces the password with the
challenge responce string
> >
> > is chap is enabled and the current container does not have a fetchChap
method an die error is thrown else fetchChap is called instead of fetchData
> >
>
> after a first look, it looks great (especialy because you implemented most
> of my suggestions :-D)
>
> just two short notes:
> - you should always inlcude the chapid into the md5-hash, even it's always
> 1, because otherwise you are breaking the RFC
> - maybe we can find a way for preparing the auth-class for different
> chap-methods (ms-chapv1 and v2), this should allow us later easier
> implement these.
>
>
>
> bye,
> --
> ------------------------------- ----------------------------------
> Michael Bretterklieber - http://www.bretterklieber.com
> JAWA Management Software GmbH - http://www.jawa.at
> Tel: ++43-(0)316-403274-12 - GSM: ++43-(0)676-84 03 15 712
> ------------------------------- ----------------------------------
> "...the number of UNIX installations has grown to 10, with more
> expected..." - Dennis Ritchie and Ken Thompson, June 1972
>