diff --git a/core/templates/installation.php b/core/templates/installation.php index 1a05c3fb76..426d60989a 100644 --- a/core/templates/installation.php +++ b/core/templates/installation.php @@ -3,7 +3,6 @@ '> '>
- 0): ?> - + +
+ t('Security Warning');?> + t('No secure random number generator is available, please enable the PHP OpenSSL extension.');?> +
+ t('Without a secure random number generator an attacker may be able to predict password reset tokens and take over your account.');?> +
+
t( 'Create an admin account' ); ?>

diff --git a/lib/setup.php b/lib/setup.php index 16b9ec68df..be4101fd7b 100644 --- a/lib/setup.php +++ b/lib/setup.php @@ -5,12 +5,14 @@ $hasMySQL = is_callable('mysql_connect'); $hasPostgreSQL = is_callable('pg_connect'); $hasOracle = is_callable('oci_connect'); $datadir = OC_Config::getValue('datadirectory', OC::$SERVERROOT.'/data'); + $opts = array( 'hasSQLite' => $hasSQLite, 'hasMySQL' => $hasMySQL, 'hasPostgreSQL' => $hasPostgreSQL, 'hasOracle' => $hasOracle, 'directory' => $datadir, + 'secureRNG' => OC_Util::secureRNG_available(), 'errors' => array(), ); diff --git a/lib/util.php b/lib/util.php index 748886083d..9fde98c197 100755 --- a/lib/util.php +++ b/lib/util.php @@ -559,6 +559,7 @@ class OC_Util { * @brief Generates a cryptographical secure pseudorandom string * @param Int with the length of the random string * @return String + * Please also update secureRNG_available if you change something here */ public static function generate_random_bytes($length = 30) { @@ -589,4 +590,27 @@ class OC_Util { } return $pseudo_byte; } + + /* + * @brief Checks if a secure random number generator is available + * @return bool + */ + public static function secureRNG_available() { + + // Check openssl_random_pseudo_bytes + if(function_exists('openssl_random_pseudo_bytes')) { + openssl_random_pseudo_bytes(1, $strong); + if($strong == TRUE) { + return true; + } + } + + // Check /dev/random + $fp = @file_get_contents('/dev/random', false, null, 0, 1); + if ($fp !== FALSE) { + return true; + } + + return false; + } }