Req #52356 [Com]: In memory support for openssl_pkcs7_*

From: Date: Mon, 13 Jan 2014 12:23:42 +0000
Subject: Req #52356 [Com]: In memory support for openssl_pkcs7_*
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183762@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52356&edit=1 ID: 52356 Comment by: php at kriegt dot es Reported by: p dot vanbrouwershaven at networking4all dot com Summary: In memory support for openssl_pkcs7_* Status: Assigned Type: Feature/Change Request Package: OpenSSL related PHP Version: Irrelevant Assigned To: pajoye Block user comment: N Private report: N New Comment: Hi, what is the status of this feature request? I really would love to see this in some of the next versions as I already asked something about that on stackoverflow: http://stackoverflow.com/questions/21053935/php-openssl-pkcs7-needs-files-security-issue If you need a free S/Mime certificate for one year for testing purposes, request it on https://www.startssl.com/ for any Mailaddress you want AND OWN ofcourse (either gmail or hotmail, whatever). There should be a way to pass the encrypted/unencrypted mail as a string variable, not as a filename. Since PKCS7_decrypt(3) says that the BIO filehandler could be even memory based. https://www.openssl.org/docs/crypto/PKCS7_encrypt.html Please check this out again. Previous Comments: ------------------------------------------------------------------------ [2010-07-16 11:00:26] p dot vanbrouwershaven at networking4all dot com You can download the zipfile here: https://docs.google.com/leaf? id=0B3a2D2VoY8NgZGEzZGIxYzQtYWFiNS00NDNkLWI2ZGQtM2Y5YjQwNjM3Yjc2&hl=en&authkey=C KeKg4cJ Please request a free 30 day trail client certificate if you don't have one already for your own. (takes just a minute, the intermediate is already included in the zipfile) http://www.globalsign.com/authentication-secure-email/digital-id/trial- personalsign.html ------------------------------------------------------------------------ [2010-07-16 10:45:24] pajoye@php.net Can you link to a zip containing what you use for this example please? May help to debug the issue you are describing while being at it. ------------------------------------------------------------------------ [2010-07-16 10:30:15] p dot vanbrouwershaven at networking4all dot com First exmaple, signing mail with the current PHP version, content is located in file unsigned.txt, strangely this file needs to start with an empty line to get the signature recognized. <?php if (openssl_pkcs7_sign("unsigned.txt", "signed.txt", "file://public.cer", array("file://private.key", "password"), array("To" => "me@example.com", // keyed syntax "From: Me <me@example.com>", // indexed syntax "Subject" => "This is my subject"), PKCS7_DETACHED, "intermediate.cer" )) { // message signed - send it! exec(ini_get("sendmail_path") . " < signed.txt"); } ?> A second example that runs with this patch, please not the linefeed "\n", without this linefeed the signature will not be recognized. <?php if (openssl_pkcs7_sign("\nunsigned.txt", "signed.txt", "file://public.cer", array("file://private.key", "password"), array("To" => "me@example.com", // keyed syntax "From: Me <me@example.com>", // indexed syntax "Subject" => "This is my subject"), PKCS7_DETACHED, "intermediate.cer" )) { // message signed - send it! exec(ini_get("sendmail_path") . " < signed.txt"); } ?> Please not this proof of concept does only changes the infilename and not the other files like the outfilename, signcert, privkey & extracerts. ------------------------------------------------------------------------ [2010-07-16 10:14:48] pajoye@php.net Thanks, will take care of them asap. Do you have some tests as well, would help to reduce the time to commit :) ------------------------------------------------------------------------ [2010-07-16 10:13:51] jille at quis dot cx Attached patch is a proof-of-concept patch. It changes openssl_pkcs7_sign() to use the input filename as a string instead of as a filename. Paul has tested this and it seems to work. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=52356 -- Edit this bug report at https://bugs.php.net/bug.php?id=52356&edit=1

« previous php.bugs (#183762) next »