What is Authentication anyway?
| From: | \[php\]Walter | Date: | Thu, 20 May 2004 15:22:36 +0000 |
| Subject: | What is Authentication anyway? | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-29457@lists.php.net to get a copy of this message | ||
A few sources define Authentication as:
Authentication
The process of identifying an individual, usually based on a username and
password. In security systems, authentication is distinct from authorization
, which is the process of giving individuals access to system objects based
on their identity. Authentication merely ensures that the individual is who
he or she claims to be, but says nothing about the access rights of the
individual.
-- www.webopedia.com
Authentication
A secure system requires that all users must identify themselves before they
can perform any other system action. Authentication is the process of
establishing the validity of the user attempting to gain access, and is thus
a basic component of access control.
The primary methods of user authentication are:
- access passwords (something the user knows)
- access tokens (something the user owns)
- biometrics (something the user is, such as a finger, palm or voice
print)
- geography (such as a particular workstation)
- user profiling (such as expected or acceptable behavior)
-- www.itsecurity.com
Synonyms: confirm.
I'm asking this because of my confusion on the current incarnation of
PEAR:Auth.
As I see it, PEAR:Auth has these "features":
Authentication methods:
* start - begins session and check login status
* login - use container[s] to validate userID and password
* logout - wipes properties and session data
* fetchData() - use container[s] to validate userid and password
and retrieve additional data (if defined)
* checkAuth() - determine if session is still valid
* getStatus() - returns current status
And User Level methods:
* listUsers() - use container[s] to list available users
* addUser() - use container[s] to add a new user
* removeUser() - use container[s] to remove an existing user
* changePassword() - use container[s] to modify password
(yes, there are more methods, but these are core)
There has been discussion here of late about what Auth does and does not do.
This subject has been touched upon previously as well. (Unfortunately, I
can't locate where in the archives, but I've read it).
The consensus then and now is that Auth is used to authenticate someone, not
to "authorize" them with any privileges or level access.
But over the last few years, User methods have been added to Auth. And when
new people to Auth (and the overall discussion) review what Auth can and
cannot (currently) do, they ask about "missing features". Like I did about
changePassword(), and others have about access rights.
So Auth has "evolved" into a pseudo User Account Maintenance Class as well
as a User Authentication Class.
So I have to ask, "what is Auth anyway?"
Is Pear:Auth just authentication?
Is Pear:Auth authentication *and* user account maintenance?
It is looking like (to me anyway) that Pear:Auth is becoming a bit
schizophrenic in this regard.
LiverUser was created to handle both authentication and access management
(or so I understand). And since my earlier messages to this and
php.pear.general on this, I've been working (off and on) on creating a new
Authorize Class, hanging off Auth. (Maybe it should be a whole User Class,
don't know yet. Thoughts?)
Anyway, I don't expect this topic to go away, just based upon the existing
methods and the messages generated asking about "missing features" (all
based upon what is there already). That's why I'm opening this topic up as I
would like to see what others feel on this
Also, as I was studying Auth, I built this chart for myself... (if this
looks weird for you, just drop into an editor and use a monospaced font to
view it, then it will line up)
listUsers() addUser() removeUser() fetchData()
changePassword()
DB X X X X
X
File X X X
X
IMAP
X
LDAP X
X
MDB X X X X
X
POP3 X
RADIUS X
SAMBA X X X
SOAP X
VpopMail
UNIX X X X X
SMBPasswd
X
MDB2 X X X X
X
What I found was that most of the Auth containers do not support the user
level methods. Again, using the original logic, they shouldn't.
Anyway...
Thanks for your time. And, even if my notes of late don't convey this, I
really do appreciate all the work that has been done on this. I can image it
can't be an easy task dealing with people who just won't quit. ;)
Walter
As an aside, I found this in the archives...
Breaking BC in not unprecedented:
- Re: Auth fix + Useful patch
- Friday, May 16, 2003 3:31 PM
- Martin Jansen
- I'm aware that this break BC, but I think that the new behavior
is the only one that makes really sense.