SessionID generation entropy?

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Ga

    #1

    SessionID generation entropy?

    Hi,

    I've got a total-newbie question: I'm playing with php session handling;
    I've written a simple login/logout script, modified from a tutorial found
    *googling* around, which prints out $PHPSESSID after user logs in.

    Well...I obtain the same SID for every username/password pair (one SID for
    each pair), while I expected different SID for every instance.

    My php.ini looks like that:

    session.entropy _lenght = 16
    session.entropy _file = /dev/random

    phpinfo() tells me these settings are effective and cat /dev/random shows
    me something which actually seems random :)

    I'm using php 4.1.2 as an Apache module on a Linux Debian box (testing
    release, kernel 2.4.22).

    What do I miss?

    G.
Working...