Bug #69197 [Opn]: $extracerts param in openssl_pkcs7_sign handles default values incorrectly
| From: | marcus at synchromedia dot co dot uk | Date: | Fri, 06 Mar 2015 17:30:08 +0000 |
| Subject: | Bug #69197 [Opn]: $extracerts param in openssl_pkcs7_sign handles default values incorrectly | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-191220@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69197&edit=1
ID: 69197
User updated by: marcus at synchromedia dot co dot uk
Reported by: marcus at synchromedia dot co dot uk
Summary: $extracerts param in openssl_pkcs7_sign handles
default values incorrectly
Status: Open
Type: Bug
Package: OpenSSL related
PHP Version: 5.6.6
Block user comment: N
Private report: N
New Comment:
Just to be clear, in my actual code I'm not passing a literal null, but a variable that may
contain null or an empty string. It behaves the same way as passing the literal values, so I chose
not to complicate it by including that.
Previous Comments:
------------------------------------------------------------------------
[2015-03-06 17:16:28] marcus at synchromedia dot co dot uk
Description:
------------
This is the signature for the openssl_pkcs7_sign function:
function openssl_pkcs7_sign($infilename, $outfilename, $signcert, $privkey, array $headers, $flags =
PKCS7_DETACHED, $extracerts = null) { }
The problem I've found is that if you provide the $extracerts param *at all*, even if it's
null (i.e. the same as its default value), it tries to open it as a file, resulting in this error:
Warning: openssl_pkcs7_sign(): error opening the file
To behave like other PHP functions, I would expect this value to be ignored when passwed with the
same value as the default. It appears to be checking for the presence of the parameter rather than
its value.
It's easy enough to work around - you can check whether you need the extracerts param and have
two different calls - but it's still a bug!
There are also issues with documentation of the parameters for this function - I've found the
$signcert and $privkey params require that you prepend the pathname with 'file://', but,
inconsistently, the $extracerts param does not.
Test script:
---------------
Example script to demonstrate the bug:
https://gist.github.com/Synchro/b9e4625013077def0cf7
A successful run should produce no output at all
Actual result:
--------------
Warning: openssl_pkcs7_sign(): error opening the file, in openssl_pkcs7_sign_bug.php on line 46
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69197&edit=1