Bug #60157 [Com]: OPENSSL_CONF environment variable ignored

From: Date: Wed, 05 Nov 2014 13:24:46 +0000
Subject: Bug #60157 [Com]: OPENSSL_CONF environment variable ignored
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188462@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60157&edit=1

 ID:                 60157
 Comment by:         cerbrst86 at yahoo dot de
 Reported by:        zeusgerde at arcor dot de
 Summary:            OPENSSL_CONF environment variable ignored
 Status:             Open
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Windows XP and Windows 7
 PHP Version:        5.3.8
 Block user comment: N
 Private report:     N

 New Comment:

####Actual result (Zend Server 7):####

Current PHP version: 5.5.13
*** OPENSSL_CONF
string(35) "/usr/local/zend/etc/ssl/openssl.cnf"

*** Errors before calling openssl_pkey_new

*** Calling openssl_pkey_new
bool(false)

*** Errors after calling openssl_pkey_new
string(61) "error:02001002:system library:fopen:No such file or directory"
string(53) "error:2006D080:BIO routines:BIO_new_file:no such file"
string(63) "error:0E064002:configuration file routines:CONF_load:system lib"
string(61) "error:02001002:system library:fopen:No such file or directory"
string(53) "error:2006D080:BIO routines:BIO_new_file:no such file"
string(63) "error:0E064002:configuration file routines:CONF_load:system lib"

####Actual Result (Zend Server 7 php-cli):####

Current PHP version: 5.5.13
*** OPENSSL_CONF
string(35) "/usr/local/zend/etc/ssl/openssl.cnf"

*** Errors before calling openssl_pkey_new

*** Calling openssl_pkey_new
resource(4) of type (OpenSSL key)

*** Errors after calling openssl_pkey_new
string(68) "error:0E06D06C:configuration file routines:NCONF_get_string:no value"
string(68) "error:0E06D06C:configuration file routines:NCONF_get_string:no value"
string(68) "error:0E06D06C:configuration file routines:NCONF_get_string:no value"
string(68) "error:0E06D06C:configuration file routines:NCONF_get_string:no value"
string(68) "error:0E06D06C:configuration file routines:NCONF_get_string:no value"
string(68) "error:0E06D06C:configuration file routines:NCONF_get_string:no value"


Previous Comments:
------------------------------------------------------------------------
[2014-05-27 11:26:04] pet at biba dot uni-bremen dot de

Under windows with f-cgi only the path "C:\usr\local\ssl" is searched for the cnf. Apache,
PHP, SSL are in PATH and OPENSSL_CONF is set too.

------------------------------------------------------------------------
[2014-02-12 22:07:34] marco at m-s-d dot eu

Confirming still present in php5.6-201402121030 with OpenSSL 1.0.7f, OS w7 x64.

------------------------------------------------------------------------
[2013-03-22 19:15:08] eugene at zhegan dot in

Still reproducible on 5.3.23.

------------------------------------------------------------------------
[2012-01-03 21:25:54] dfroe at gmx dot de

I am able to reproduce this bug under FreeBSD, too. So it does not seem to be a Windows specific
issue. I am using PHP 5.3.8 compiled via the latest FreeBSD ports tree. The putenv() hint does not
work, either. Passing the config value within the config array directly to the openssl function
works - but can of course only be a quick and dirty workaround.

------------------------------------------------------------------------
[2011-10-31 07:51:05] zeusgerde at arcor dot de

> Where do you set it? System wild? manually in your script?

In httpd.conf in a global scope:
| SetEnv OPENSSL_CONF D:\sandbox\openssl.cnf

You can see that it is set in the actual result:
| var_dump(getenv('OPENSSL_CONF'));
| // string(42) "D:\sandbox\openssl.cnf"

(hint: don't look at the string length, I scrambled the path in this bug report)

> putenv("OPENSSL_CONF=whereyouwanit");

No change in the actual result. Even if I do this:

| putenv("OPENSSL_CONF=", getenv('OPENSSL_CONF'));

It only works if I use the $configargs parameter directly (see my first comment 
at 2011-10-28 11:48 UTC)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=60157


--
Edit this bug report at https://bugs.php.net/bug.php?id=60157&edit=1


Thread (10 messages)

« previous php.bugs (#188462) next »