PEAR is archived and read-only

This mirror preserves historical PEAR package releases and metadata so existing references remain available.

Home » Authentication » LiveUser » Bug #6551

Secret key in conf.php not taken into account

Details

Submitted2006-01-22 18:54 UTC
Fromgoethals_d at hotmail dot com
Assignedlsmith
StatusClosed
PackageLiveUser
PHP Version5.0.4
OSWXP
Roadmaps(Not assigned)

Comments

[2006-01-22 18:54 UTC] goethals_d at hotmail dot com

Description:
------------
Set encryption mode to RC4 in configuration file.
If the secret key is set to 'test', I can login. If I modify the secret key to 'word' without changing the DB contents, I can still login.
Note that the password encrypted with LiveUser::Crypt_RC4 or the password encrypted with PEAR::Crypt_RC4 using the same secret key do not match.

Test script:
---------------
conf.php
...
'authContainers' => array(
array(
'type' => 'MDB2',
'expireTime' => 3600,
'idleTime' => 1800,
'allowDuplicateHandles' => 0,
'allowEmptyPasswords' => 0,
'passwordEncryptionMode'=> 'RC4',
'secret' => 'test',
...