Req #67403 [Com]: Add signatureType to openssl_x509_parse

From: Date: Tue, 10 Jun 2014 13:31:42 +0000
Subject: Req #67403 [Com]: Add signatureType to openssl_x509_parse
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186132@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67403&edit=1 ID: 67403 Comment by: zelnaga at gmail dot com Reported by: mark at zedwood dot com Summary: Add signatureType to openssl_x509_parse Status: Open Type: Feature/Change Request Package: OpenSSL related Operating System: Ubuntu 14.04 PHP Version: 5.5.13 Block user comment: N Private report: N New Comment: FWIW you can get this info with phpseclib, a pure PHP X.509 decoder: <?php include('File/X509.php'); $x509 = new File_X509(); $cert = $x509->loadX509('-----BEGIN CERTIFICATE----- MIIBBzCBrgIJANZXs2GIGRy3MAoGCCqGSM49BAMDMAwxCjAIBgNVBAMMAXgwHhcN MTQwNjA5MTczMjQ1WhcNMjQwNjA2MTczMjQ1WjAMMQowCAYDVQQDDAF4MFkwEwYH KoZIzj0CAQYIKoZIzj0DAQcDQgAEK8KP9tJ1bZxLGKqNP9JpOkaq9paKoMS4/0wm 6u62b0mArY7xmS5/Nlkyi/GK21QpjSk4vRwkN+tYPeAy/8Bd2TAKBggqhkjOPQQD AwNIADBFAiAjVRQZKlKCBzJxJ7aw8qRrZUhBczX9psneshOhI7g4mQIhAPlTbP67 mq9Qf/YphH6gWZXX50TGC2OTOUXRm60Cajs3 -----END CERTIFICATE-----'); echo $cert['signatureAlgorithm']['algorithm']; ?> That said "sha256WithRSAEncryption" isn't your signature type. sha384ECDSA is. And the OID that corresponds to that signature type doesn't seem to be recognized by OpenSSL. At least not the version I'm using. When I try it with OpenSSL (or phpseclib) I just get the OID: 1.2.840.10045.4.3.3 Previous Comments: ------------------------------------------------------------------------ [2014-06-09 17:46:09] mark at zedwood dot com Description: ------------ One of the main attributes of an x509 certificate that is not parsed or exposed in openssl_x509_parse, is the signature type. On a linux command line, running "cat my.pem|openssl x509 -noout -text" does provide the signature type, but there should be a native way in php to parse this out of a certificate without having to fallback to the command line. Reading the source code, it looks like someone else tried to add it, but left it commented out, see: ext/openssl/openssl.c around line 1540... /* add_assoc_long(return_value, "signaturetypeLONG", X509_get_signature_type(cert)); add_assoc_string(return_value, "signaturetype", OBJ_nid2sn(X509_get_signature_type(cert)), 1); add_assoc_string(return_value, "signaturetypeLN", OBJ_nid2ln(X509_get_signature_type(cert)), 1); */ It was commented out, because the code did not work. Perhaps there is a way to provide this functionality. Test script: --------------- <?php $cert=<<<EOF -----BEGIN CERTIFICATE----- MIIBBzCBrgIJANZXs2GIGRy3MAoGCCqGSM49BAMDMAwxCjAIBgNVBAMMAXgwHhcN MTQwNjA5MTczMjQ1WhcNMjQwNjA2MTczMjQ1WjAMMQowCAYDVQQDDAF4MFkwEwYH KoZIzj0CAQYIKoZIzj0DAQcDQgAEK8KP9tJ1bZxLGKqNP9JpOkaq9paKoMS4/0wm 6u62b0mArY7xmS5/Nlkyi/GK21QpjSk4vRwkN+tYPeAy/8Bd2TAKBggqhkjOPQQD AwNIADBFAiAjVRQZKlKCBzJxJ7aw8qRrZUhBczX9psneshOhI7g4mQIhAPlTbP67 mq9Qf/YphH6gWZXX50TGC2OTOUXRm60Cajs3 -----END CERTIFICATE----- EOF; $r = openssl_x509_parse($cert); echo $r['signatureType']."\n"; Expected result: ---------------- string(23) "sha256WithRSAEncryption" Actual result: -------------- NULL ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67403&edit=1

« previous php.bugs (#186132) next »