Edit report at https://bugs.php.net/bug.php?id=51647&edit=1
ID: 51647
Comment by: rdlowrey@php.net
Reported by: andrey@php.net
Summary: Certificate file without private key (pk in another
file) doesn't work
Status: Assigned
Type: Bug
Package: OpenSSL related
Operating System: Linux
PHP Version: 5.3SVN-2010-04-23 (SVN)
Assigned To: pajoye
Block user comment: N
Private report: N
New Comment:
> The user is forced to put keys in the same file,
> which is not always possible.
I'm drawing a blank on when this would not be possible. The only thing that needs to happen in
order for this to work is the concatenation of the private key and the public cert into the same
file.
Are there scenarios where this isn't possible that I'm missing? Otherwise I wouldn't
really consider this a bug.
Previous Comments:
------------------------------------------------------------------------
[2014-01-30 17:46:28] daverandom@php.net
Pierre/Andrey
Are we happy that this bug is fixed? The context option that was added by the patch is not currently
documented. I will be helping to update the documentation for the recent OpenSSL changes, can I
include this in the docs as well?
Thanks, Chris
------------------------------------------------------------------------
[2010-04-23 17:28:54] andrey@php.net
Here is the new patch, already committed, also to be found in the commit email.
Index: ext/openssl/openssl.c
===================================================================
--- ext/openssl/openssl.c (revision 298371)
+++ ext/openssl/openssl.c (working copy)
@@ -4445,6 +4445,7 @@
EVP_PKEY *key = NULL;
SSL *tmpssl;
char resolved_path_buff[MAXPATHLEN];
+ const char * private_key = NULL;
if (VCWD_REALPATH(certfile, resolved_path_buff)) {
/* a certificate to use for authentication */
@@ -4452,10 +4453,21 @@
php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set local cert chain file
`%s'; Check that your cafile/capath settings include details of your certificate and its
issuer", certfile);
return NULL;
}
+ GET_VER_OPT_STRING("local_pk", private_key);
- if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff, SSL_FILETYPE_PEM) != 1) {
- php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file
`%s'", resolved_path_buff);
- return NULL;
+ if (private_key) {
+ char resolved_path_buff_pk[MAXPATHLEN];
+ if (VCWD_REALPATH(private_key, resolved_path_buff_pk)) {
+ if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff_pk, SSL_FILETYPE_PEM) != 1) {
+ php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file
`%s'", resolved_path_buff_pk);
+ return NULL;
+ }
+ }
+ } else {
+ if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff, SSL_FILETYPE_PEM) != 1) {
+ php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file
`%s'", resolved_path_buff);
+ return NULL;
+ }
}
tmpssl = SSL_new(ctx);
------------------------------------------------------------------------
[2010-04-23 17:18:15] andrey@php.net
Pierre, I haven't committed the same wrong thing. I thought you can read emails/diffs, but
somehow I lost this feeling.
------------------------------------------------------------------------
[2010-04-23 17:15:24] andrey@php.net
You need to start the MySQL server with the following options :
ssl-ca=/path/to/cacert.pem
ssl-cert=/path/to/server-cert.pem
ssl-key=/path/to/server-key.pem
All files you can find here:
http://www.hristov.com/andrey/projects/php_stuff/certs/
------------------------------------------------------------------------
[2010-04-23 16:30:09] pajoye@php.net
To open a bug, commit the same wrong thing and close the bug does not solve anything. I mailed you
what I'm expecting.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=51647
--
Edit this bug report at https://bugs.php.net/bug.php?id=51647&edit=1