From: Marc L. <ma...@ma...> - 2017-03-24 18:40:16
|
FYI, Ricardo just updated https://github.com/phpseclib/phpseclib to latest version and deprecated https://github.com/phpsec/phpSec https://sourceforge.net/p/tikiwiki/code/61780 Maybe phpseclib has what is needed? Or else perhaps in Zend Framework? Thanks! On Tue, Mar 21, 2017 at 7:36 AM, Arild Berg <be...@sa...> wrote: > > The MCrypt library is used in Tiki, but it has not been maintained since > 2007. > For this reason it has been marked as depreciated in PHP 7.1 and will be > moved out of the standard PHP installation to PECL in PHP 7.2 > For details see: https://secure.php.net/manual/en/intro.mcrypt.php > > This means that all modules using MCrypt will fail to work "out of the > box" pretty soon. > For this reason Tiki should replace MCrypt with another maintained crypto > library. > > Some questions > - Which Tiki versions should be updated? > - To which crypto library should the Tiki code be migrated? > - Which modules in Tiki are affected? > - How should the data migration process work? > > One module that will be affected is the User Encryption. > In my (limited) searches so far, it seems like the alternative libraries > do not encrypt/decrypt the same way as MCrypt. > The recommended upgrade procedure seems to be... > 1) Decrypt using MCrypt > 2) Encrypt using the new library > This may cause a problem for the User Encryption, since the user's > password in plaintext must be known to decrypt the data. > The plaintext password is only known when the user logs in. > > It would be good to collect some more thoughts, before the code migration > is started. > > Thanks to Bernard for raising the issue. > > Arild > > > > <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient&utm_term=icon> Virus-free. > www.avast.com > <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient&utm_term=link> > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > TikiWiki-devel mailing list > Tik...@li... > https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel > > -- Marc Laporte http://WikiSuite.org http://PluginProblems.com http://Avan.Tech |