Edit report at https://bugs.php.net/bug.php?id=69882&edit=1
ID: 69882
User updated by: falundir at gmail dot com
Reported by: falundir at gmail dot com
Summary: OpenSSL âkey values mismatchâ on SOAP HTTPS
mixed with openssl_pkcs12_read
Status: Open
Type: Bug
Package: OpenSSL related
Operating System: Debian 8.0
PHP Version: 5.6.7
Block user comment: N
Private report: N
New Comment:
I have been able to "fix" this error by calling ERR_get_error() at the cleanup section of
openssl_pkcs12_read method. Something in there is producing this "key values mismatch"
error and since it's not consumed in this method, it is picked up by php_openssl_sockop_io.
Change in this commit introduced a line:
int err = SSL_get_error(sslsock->ssl_handle, nr_bytes );
before:
retry = handle_ssl_error(stream, nr_bytes, 0 TSRMLS_CC);
which effectively cleared SSL error from handle_ssl_error and made handle_ssl_error go to default
section of switch where ERR_get_error() is handled.
If this change is OK or not is another case, but primary case would be to check what is producing
"key values mismatch" error at openssl_pkcs12_read and handle it there properly.
Previous Comments:
------------------------------------------------------------------------
[2015-06-22 08:49:18] falundir at gmail dot com
I've located the specific commit which indroduced the bug:
fd4641696cc67fedf494717b5e4d452019f04d6f (together with next
1482ed2d5660c3875add40706a18fe29e2b3ff70).
------------------------------------------------------------------------
[2015-06-21 20:16:58] falundir at gmail dot com
Verified that PHP 5.6.7 is the first version with this bug. Tested by compiling from the source, so
it's not a problem in Debian packaged version.
------------------------------------------------------------------------
[2015-06-19 10:31:32] falundir at gmail dot com
Fixed summary.
------------------------------------------------------------------------
[2015-06-19 10:30:28] falundir at gmail dot com
Description:
------------
Following scenario:
1. Call some SOAP method with HTTPS endpoint.
2. Call openssl_pkcs12_read on PKCS#12 file with extra certificates.
3. Call some SOAP method with HTTPS endpoint again. It will cause warning.
Causes warning:
Warning: SoapClient::__doRequest(): SSL operation failed with code 1. OpenSSL Error messages:
error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch
followed by:
Fatal error: Uncaught SoapFault exception: [HTTP] Error Fetching http headers
Versions affected are at least PHP 5.6.9 (Debian 8) and PHP 7.0.0-dev (tested on Rasmus's
php7dev Vagrant box image from https://github.com/rlerdorf/php7dev.git). It
worked OK in Debian 7 (PHP 5.4).
More details and full working test case with certificate and public SOAP webservice available at http://stackoverflow.com/questions/30730846.
Test script:
---------------
$p12 = file_get_contents('certificate_with_private_key_and_extra_certs.p12');
$p12_password = 'password';
$sc = new SoapClient('URL to SOAP webservice with HTTPS endpoint');
var_dump($sc->method());
$result = openssl_pkcs12_read($p12, $cert_data, $p12_password);
var_dump($sc->method()); //this causes warning and soap exception
Expected result:
----------------
<var dumped result of $sc->method()>
<var dumped result of $sc->method()>
Actual result:
--------------
<var dumped result of $sc->method()>
Warning: SoapClient::__doRequest(): SSL operation failed with code 1. OpenSSL Error messages:
error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch
Fatal error: Uncaught SoapFault exception: [HTTP] Error Fetching http headers
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69882&edit=1