mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #06780
[Bug 888424] [NEW] Warn admins if session.entropy_length is < 16
Public bug reported:
The session.entropy_length variable in php.ini controls how much entropy
is used when generating session keys:
http://nz.php.net/manual/en/session.configuration.php#ini.session
.entropy-length
OWASP recommends that session keys contain at least 128 bits (16 bytes)
of entropy so we should print a warning on the admin page to let admins
know that they should set this variable to a larger number (it
unfortunately defaults to 0).
** Affects: mahara
Importance: Medium
Status: Confirmed
** Tags: security sessions
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
https://bugs.launchpad.net/bugs/888424
Title:
Warn admins if session.entropy_length is < 16
Status in Mahara ePortfolio:
Confirmed
Bug description:
The session.entropy_length variable in php.ini controls how much
entropy is used when generating session keys:
http://nz.php.net/manual/en/session.configuration.php#ini.session
.entropy-length
OWASP recommends that session keys contain at least 128 bits (16
bytes) of entropy so we should print a warning on the admin page to
let admins know that they should set this variable to a larger number
(it unfortunately defaults to 0).
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/888424/+subscriptions
Follow ups
References