What is Authentication anyway?

From: Date: Thu, 20 May 2004 15:22:36 +0000
Subject: What is Authentication anyway?
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-29457@lists.php.net to get a copy of this message
A few sources define Authentication as: Authentication The process of identifying an individual, usually based on a username and password. In security systems, authentication is distinct from authorization , which is the process of giving individuals access to system objects based on their identity. Authentication merely ensures that the individual is who he or she claims to be, but says nothing about the access rights of the individual. -- www.webopedia.com Authentication A secure system requires that all users must identify themselves before they can perform any other system action. Authentication is the process of establishing the validity of the user attempting to gain access, and is thus a basic component of access control. The primary methods of user authentication are: - access passwords (something the user knows) - access tokens (something the user owns) - biometrics (something the user is, such as a finger, palm or voice print) - geography (such as a particular workstation) - user profiling (such as expected or acceptable behavior) -- www.itsecurity.com Synonyms: confirm. I'm asking this because of my confusion on the current incarnation of PEAR:Auth. As I see it, PEAR:Auth has these "features": Authentication methods: * start - begins session and check login status * login - use container[s] to validate userID and password * logout - wipes properties and session data * fetchData() - use container[s] to validate userid and password and retrieve additional data (if defined) * checkAuth() - determine if session is still valid * getStatus() - returns current status And User Level methods: * listUsers() - use container[s] to list available users * addUser() - use container[s] to add a new user * removeUser() - use container[s] to remove an existing user * changePassword() - use container[s] to modify password (yes, there are more methods, but these are core) There has been discussion here of late about what Auth does and does not do. This subject has been touched upon previously as well. (Unfortunately, I can't locate where in the archives, but I've read it). The consensus then and now is that Auth is used to authenticate someone, not to "authorize" them with any privileges or level access. But over the last few years, User methods have been added to Auth. And when new people to Auth (and the overall discussion) review what Auth can and cannot (currently) do, they ask about "missing features". Like I did about changePassword(), and others have about access rights. So Auth has "evolved" into a pseudo User Account Maintenance Class as well as a User Authentication Class. So I have to ask, "what is Auth anyway?" Is Pear:Auth just authentication? Is Pear:Auth authentication *and* user account maintenance? It is looking like (to me anyway) that Pear:Auth is becoming a bit schizophrenic in this regard. LiverUser was created to handle both authentication and access management (or so I understand). And since my earlier messages to this and php.pear.general on this, I've been working (off and on) on creating a new Authorize Class, hanging off Auth. (Maybe it should be a whole User Class, don't know yet. Thoughts?) Anyway, I don't expect this topic to go away, just based upon the existing methods and the messages generated asking about "missing features" (all based upon what is there already). That's why I'm opening this topic up as I would like to see what others feel on this Also, as I was studying Auth, I built this chart for myself... (if this looks weird for you, just drop into an editor and use a monospaced font to view it, then it will line up) listUsers() addUser() removeUser() fetchData() changePassword() DB X X X X X File X X X X IMAP X LDAP X X MDB X X X X X POP3 X RADIUS X SAMBA X X X SOAP X VpopMail UNIX X X X X SMBPasswd X MDB2 X X X X X What I found was that most of the Auth containers do not support the user level methods. Again, using the original logic, they shouldn't. Anyway... Thanks for your time. And, even if my notes of late don't convey this, I really do appreciate all the work that has been done on this. I can image it can't be an easy task dealing with people who just won't quit. ;) Walter As an aside, I found this in the archives... Breaking BC in not unprecedented: - Re: Auth fix + Useful patch - Friday, May 16, 2003 3:31 PM - Martin Jansen - I'm aware that this break BC, but I think that the new behavior is the only one that makes really sense.

« previous php.pear.dev (#29457) next »