Bug #69197 [NEW]: $extracerts param in openssl_pkcs7_sign handles default values incorrectly
From: marcus at synchromedia dot co dot uk
Operating system:
PHP version: 5.6.6
Package: OpenSSL related
Bug Type: Bug
Bug description:$extracerts param in openssl_pkcs7_sign handles default values incorrectly
Description:
------------
This is the signature for the openssl_pkcs7_sign function:
function openssl_pkcs7_sign($infilename, $outfilename, $signcert,
$privkey, array $headers, $flags = PKCS7_DETACHED, $extracerts = null) {
}
The problem I've found is that if you provide the $extracerts param *at
all*, even if it's null (i.e. the same as its default value), it tries
to open it as a file, resulting in this error:
Warning: openssl_pkcs7_sign(): error opening the file
To behave like other PHP functions, I would expect this value to be
ignored when passwed with the same value as the default. It appears to
be checking for the presence of the parameter rather than its value.
It's easy enough to work around - you can check whether you need the
extracerts param and have two different calls - but it's still a bug!
There are also issues with documentation of the parameters for this
function - I've found the $signcert and $privkey params require that you
prepend the pathname with 'file://', but, inconsistently, the
$extracerts param does not.
Test script:
---------------
Example script to demonstrate the bug:
https://gist.github.com/Synchro/b9e4625013077def0cf7
A successful run should produce no output at all
Actual result:
--------------
Warning: openssl_pkcs7_sign(): error opening the file, in
openssl_pkcs7_sign_bug.php on line 46
--
Edit bug report at https://bugs.php.net/bug.php?id=69197&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69197&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69197&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69197&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69197&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69197&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69197&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69197&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69197&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69197&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69197&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69197&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69197&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69197&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69197&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69197&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69197&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69197&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69197&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69197&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69197&r=mysqlcfg
Thread (4 messages)
- marcus at synchromedia dot co dot uk