Bug #51647 [Com]: Certificate file without private key (pk in another file) doesn't work

From: Date: Tue, 04 Mar 2014 18:55:13 +0000
Subject: Bug #51647 [Com]: Certificate file without private key (pk in another file) doesn't work
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184517@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=51647&edit=1

 ID:                 51647
 Comment by:         rdlowrey@php.net
 Reported by:        andrey@php.net
 Summary:            Certificate file without private key (pk in another
                     file) doesn't work
 Status:             Assigned
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Linux
 PHP Version:        5.3SVN-2010-04-23 (SVN)
 Assigned To:        pajoye
 Block user comment: N
 Private report:     N

 New Comment:

> The user is forced to put keys in the same file,
> which is not always possible.

I'm drawing a blank on when this would not be possible. The only thing that needs to happen in
order for this to work is the concatenation of the private key and the public cert into the same
file.

Are there scenarios where this isn't possible that I'm missing? Otherwise I wouldn't
really consider this a bug.


Previous Comments:
------------------------------------------------------------------------
[2014-01-30 17:46:28] daverandom@php.net

Pierre/Andrey

Are we happy that this bug is fixed? The context option that was added by the patch is not currently
documented. I will be helping to update the documentation for the recent OpenSSL changes, can I
include this in the docs as well?

Thanks, Chris

------------------------------------------------------------------------
[2010-04-23 17:28:54] andrey@php.net

Here is the new patch, already committed, also to be found in the commit email.

Index: ext/openssl/openssl.c
===================================================================
--- ext/openssl/openssl.c	(revision 298371)
+++ ext/openssl/openssl.c	(working copy)
@@ -4445,6 +4445,7 @@
 		EVP_PKEY *key = NULL;
 		SSL *tmpssl;
 		char resolved_path_buff[MAXPATHLEN];
+		const char * private_key = NULL;
 
 		if (VCWD_REALPATH(certfile, resolved_path_buff)) {
 			/* a certificate to use for authentication */
@@ -4452,10 +4453,21 @@
 				php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set local cert chain file
`%s'; Check that your cafile/capath settings include details of your certificate and its
issuer", certfile);
 				return NULL;
 			}
+			GET_VER_OPT_STRING("local_pk", private_key);
 
-			if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff, SSL_FILETYPE_PEM) != 1) {
-				php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file
`%s'", resolved_path_buff);
-				return NULL;
+			if (private_key) {
+				char resolved_path_buff_pk[MAXPATHLEN];
+				if (VCWD_REALPATH(private_key, resolved_path_buff_pk)) {
+					if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff_pk, SSL_FILETYPE_PEM) != 1) {
+						php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file
`%s'", resolved_path_buff_pk);
+						return NULL;
+					}
+				}
+			} else {
+				if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff, SSL_FILETYPE_PEM) != 1) {
+					php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file
`%s'", resolved_path_buff);
+					return NULL;
+				}		
 			}
 
 			tmpssl = SSL_new(ctx);

------------------------------------------------------------------------
[2010-04-23 17:18:15] andrey@php.net

Pierre, I haven't committed the same wrong thing. I thought you can read emails/diffs, but
somehow I lost this feeling.

------------------------------------------------------------------------
[2010-04-23 17:15:24] andrey@php.net

You need to start the MySQL server with the following options :
ssl-ca=/path/to/cacert.pem
ssl-cert=/path/to/server-cert.pem
ssl-key=/path/to/server-key.pem

All files you can find here:
http://www.hristov.com/andrey/projects/php_stuff/certs/

------------------------------------------------------------------------
[2010-04-23 16:30:09] pajoye@php.net

To open a bug, commit the same wrong thing and close the bug does not solve anything. I mailed you
what I'm expecting.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=51647


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=51647&edit=1


Thread (11 messages)

« previous php.bugs (#184517) next »