Skip to content

RDKEMW-25973 : Enable PHP session entropy to strengthen session ID generation - #193

Open
andrejz2 wants to merge 2 commits into
developfrom
topic/RDKEMW-25973
Open

andrejz2 wants to merge 2 commits into
developfrom
topic/RDKEMW-25973

Conversation

@andrejz2

@andrejz2 andrejz2 commented Sep 30, 2026 •

Copy link
Copy Markdown

RDKEMW-25973: Enable PHP session entropy to strengthen session ID generation

Enable session.entropy_file = /dev/urandom and session.entropy_length = 16 to use cryptographic entropy for PHP session ID generation. This prevents weak session IDs that could be predicted or brute-forced.

Adds a focused security regression test that verifies the entropy settings are configured.

Parent Story: RDKEMW-25944

Reason for change: Security remediation for vulnerability identified in FAIM harness analysis.

Test Procedure: Run the focused security regression test added in this PR. Verify the security fix is in place and the vulnerability is mitigated.

Risks: Low

Priority: P2

Parent Story: RDKEMW-25944

…eration

Enable session.entropy_file = /dev/urandom and session.entropy_length = 16 to use cryptographic entropy for PHP session ID generation. This prevents weak session IDs that could be predicted or brute-forced.

Adds a focused security regression test that verifies the entropy settings are configured.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@andrejz2
andrejz2 requested review from a team as code owners September 30, 2026 03:18
Copilot AI balanced review requested due to automatic review settings September 30, 2026 03:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@rdkcmf-jenkins

Copy link
Copy Markdown
Contributor

b'## Blackduck scan failure details

Summary: 0 violations, 1 file pending approval, 0 files pending identification.

  • Protex Server Path: /home/blackduck/github/webui/193/rdkb/components/opensource/ccsp/webui

  • Commit: 503942b

Report detail: gist'

@andrejz2 andrejz2 changed the title RDKEMW-25973: Enable PHP session entropy to strengthen session ID generation RDKEMW-25973 : Enable PHP session entropy to strengthen session ID generation Sep 30, 2026
@andrejz2 andrejz2 changed the title RDKEMW-25973 : Enable PHP session entropy to strengthen session ID generation RDKEMW-25973 : Enable PHP session entropy to strengthen session ID generation Sep 30, 2026
Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com]
@rdkcmf-jenkins

Copy link
Copy Markdown
Contributor

b'## Blackduck scan failure details

Summary: 0 violations, 1 file pending approval, 0 files pending identification.

  • Protex Server Path: /home/blackduck/github/webui/193/rdkb/components/opensource/ccsp/webui

  • Commit: d776ba7

Report detail: gist'

@rdkcmf-jenkins

Copy link
Copy Markdown
Contributor

b'## Blackduck scan failure details

Summary: 0 violations, 1 file pending approval, 0 files pending identification.

  • Protex Server Path: /home/blackduck/github/webui/193/rdkb/components/opensource/ccsp/webui

  • Commit: d776ba7

Report detail: gist'

@rdkcmf-jenkins

Copy link
Copy Markdown
Contributor

b'## Blackduck scan failure details

Summary: 0 violations, 1 file pending approval, 0 files pending identification.

  • Protex Server Path: /home/blackduck/github/webui/193/rdkb/components/opensource/ccsp/webui

  • Commit: d776ba7

Report detail: gist'

@rdkcmf-jenkins

Copy link
Copy Markdown
Contributor

b'## WARNING: A Blackduck scan failure has been waived

A prior failure has been upvoted

  • Upvote reason: ok

  • Commit: d776ba7
    '

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants