Req #52356 [Com]: In memory support for openssl_pkcs7_*

From: Date: Mon, 13 Jan 2014 15:10:34 +0000
Subject: Req #52356 [Com]: In memory support for openssl_pkcs7_*
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183772@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52356&edit=1

 ID:                 52356
 Comment by:         php at kriegt dot es
 Reported by:        p dot vanbrouwershaven at networking4all dot com
 Summary:            In memory support for openssl_pkcs7_*
 Status:             Assigned
 Type:               Feature/Change Request
 Package:            OpenSSL related
 PHP Version:        Irrelevant
 Assigned To:        pajoye
 Block user comment: N
 Private report:     N

 New Comment:

Since I see no chance to change the current functions (openssl_pkcs7_encrypt/decrypt) to the schema
I would need it, I just added two new functions named:
- openssl_pkcs7_mem_encrypt
- openssl_pkcs7_mem_decrypt

These functions use BIO_s_mem instead of BIO_s_file to create the necessary BIO data handled by the
PKCS7 functions.
I tested this with the following skript and it worked as it should:

<?php
$message = "hey there, this is top secret message which gets encrypted by memory soon";
#$infile =  tempnam(sys_get_temp_dir(),'smime');
#$tmpfile = fopen( $infile, 'w+' );
#fwrite($tmpfile,$message,strlen($message));
#echo "Raw Message in $infile\n";

#$outfile = tempnam(sys_get_temp_dir(),'smime');

$certfile = "/path/to/just/the/certificate.pem";

$encrypted = "";
if( openssl_pkcs7_mem_encrypt( $message, $encrypted, file_get_contents($certfile), array() ) ) {
    var_dump( $encrypted );
}
$p12key = "/my/path/to/related/p12file.p12"
$password = "mysecretpasswordforkey";
openssl_pkcs12_read(file_get_contents($p12key), $certdata, $password);

$key = $certdata['pkey'];
$cert = $certdata['cert'];

if( strlen($key) != 0 ) {
#    echo "Key okay!\n";
}

if( trim($encrypted) != "" ) {
    if( openssl_pkcs7_mem_decrypt( $encrypted, $decrypted, $cert, array( $key, $password ) ) ) {
        var_dump( $decrypted );
    }
}


#################
First var_dump returns encrypted data
Second var_dump returns content of $message


Previous Comments:
------------------------------------------------------------------------
[2014-01-13 12:23:41] php at kriegt dot es

Hi,
what is the status of this feature request? I really would love to see this in some of the next
versions as I already asked something about that on stackoverflow:
http://stackoverflow.com/questions/21053935/php-openssl-pkcs7-needs-files-security-issue


If you need a free S/Mime certificate for one year for testing purposes, request it on https://www.startssl.com/ for any Mailaddress you want AND OWN
ofcourse (either gmail or hotmail, whatever).

There should be a way to pass the encrypted/unencrypted mail as a string variable, not as a
filename. Since PKCS7_decrypt(3) says that the BIO filehandler could be even memory based. 
https://www.openssl.org/docs/crypto/PKCS7_encrypt.html

Please check this out again.

------------------------------------------------------------------------
[2010-07-16 11:00:26] p dot vanbrouwershaven at networking4all dot com

You can download the zipfile here:

https://docs.google.com/leaf?
id=0B3a2D2VoY8NgZGEzZGIxYzQtYWFiNS00NDNkLWI2ZGQtM2Y5YjQwNjM3Yjc2&hl=en&authkey=C
KeKg4cJ

Please request a free 30 day trail client certificate if you don't have one 
already for your own. (takes just a minute, the intermediate is already included 
in the zipfile)

http://www.globalsign.com/authentication-secure-email/digital-id/trial-
personalsign.html

------------------------------------------------------------------------
[2010-07-16 10:45:24] pajoye@php.net

Can you link to a zip containing what you use for this example please? May help to debug the issue
you are describing while being at it.

------------------------------------------------------------------------
[2010-07-16 10:30:15] p dot vanbrouwershaven at networking4all dot com

First exmaple, signing mail with the current PHP version, content is located in 
file unsigned.txt, strangely this file needs to start with an empty line to get 
the signature recognized.

<?php
if (openssl_pkcs7_sign("unsigned.txt", "signed.txt",
"file://public.cer",
    array("file://private.key", "password"),
    array("To" => "me@example.com", // keyed syntax
          "From: Me <me@example.com>", // indexed syntax
          "Subject" => "This is my subject"),
    PKCS7_DETACHED,
    "intermediate.cer"
    )) {
    // message signed - send it!
    exec(ini_get("sendmail_path") . " < signed.txt");
}
?>

A second example that runs with this patch, please not the linefeed "\n", 
without this linefeed the signature will not be recognized.

<?php
if (openssl_pkcs7_sign("\nunsigned.txt", "signed.txt",
"file://public.cer",
    array("file://private.key", "password"),
    array("To" => "me@example.com", // keyed syntax
          "From: Me <me@example.com>", // indexed syntax
          "Subject" => "This is my subject"),
    PKCS7_DETACHED,
    "intermediate.cer"
    )) {
    // message signed - send it!
    exec(ini_get("sendmail_path") . " < signed.txt");
}
?>

Please not this proof of concept does only changes the infilename and not the 
other files like the outfilename, signcert, privkey & extracerts.

------------------------------------------------------------------------
[2010-07-16 10:14:48] pajoye@php.net

Thanks, will take care of them asap. Do you have some tests as well, would help to reduce the time
to commit :)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=52356


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=52356&edit=1


Thread (10 messages)

« previous php.bugs (#183772) next »