Bug #69882 [Opn]: OpenSSL “key values mismatch” on SOAP HTTPS mixed with openssl_pkcs12_read

From: Date: Tue, 23 Jun 2015 07:09:18 +0000
Subject: Bug #69882 [Opn]: OpenSSL “key values mismatch” on SOAP HTTPS mixed with openssl_pkcs12_read
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193777@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69882&edit=1 ID: 69882 User updated by: falundir at gmail dot com Reported by: falundir at gmail dot com Summary: OpenSSL “key values mismatch” on SOAP HTTPS mixed with openssl_pkcs12_read Status: Open Type: Bug Package: OpenSSL related Operating System: Debian 8.0 PHP Version: 5.6.7 Block user comment: N Private report: N New Comment: The "key values mismatch" is triggered in openssl_pkcs12_read by PKCS12_parse, because it uses X509_check_private_key to separate main certificate (which corresponds to private key) from extra certificates. Extra certificates usually comes first (p12 contents are reversed as stack) and X509_check_private_key triggers X509_R_KEY_VALUES_MISMATCH error. I guess, the fix will be to pop any X509_R_KEY_VALUES_MISMATCH errors when there are extra certificates. Will try that. Previous Comments: ------------------------------------------------------------------------ [2015-06-22 19:48:08] falundir at gmail dot com I have been able to "fix" this error by calling ERR_get_error() at the cleanup section of openssl_pkcs12_read method. Something in there is producing this "key values mismatch" error and since it's not consumed in this method, it is picked up by php_openssl_sockop_io. Change in this commit introduced a line: int err = SSL_get_error(sslsock->ssl_handle, nr_bytes ); before: retry = handle_ssl_error(stream, nr_bytes, 0 TSRMLS_CC); which effectively cleared SSL error from handle_ssl_error and made handle_ssl_error go to default section of switch where ERR_get_error() is handled. If this change is OK or not is another case, but primary case would be to check what is producing "key values mismatch" error at openssl_pkcs12_read and handle it there properly. ------------------------------------------------------------------------ [2015-06-22 08:49:18] falundir at gmail dot com I've located the specific commit which indroduced the bug: fd4641696cc67fedf494717b5e4d452019f04d6f (together with next 1482ed2d5660c3875add40706a18fe29e2b3ff70). ------------------------------------------------------------------------ [2015-06-21 20:16:58] falundir at gmail dot com Verified that PHP 5.6.7 is the first version with this bug. Tested by compiling from the source, so it's not a problem in Debian packaged version. ------------------------------------------------------------------------ [2015-06-19 10:31:32] falundir at gmail dot com Fixed summary. ------------------------------------------------------------------------ [2015-06-19 10:30:28] falundir at gmail dot com Description: ------------ Following scenario: 1. Call some SOAP method with HTTPS endpoint. 2. Call openssl_pkcs12_read on PKCS#12 file with extra certificates. 3. Call some SOAP method with HTTPS endpoint again. It will cause warning. Causes warning: Warning: SoapClient::__doRequest(): SSL operation failed with code 1. OpenSSL Error messages: error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch followed by: Fatal error: Uncaught SoapFault exception: [HTTP] Error Fetching http headers Versions affected are at least PHP 5.6.9 (Debian 8) and PHP 7.0.0-dev (tested on Rasmus's php7dev Vagrant box image from https://github.com/rlerdorf/php7dev.git). It worked OK in Debian 7 (PHP 5.4). More details and full working test case with certificate and public SOAP webservice available at http://stackoverflow.com/questions/30730846. Test script: --------------- $p12 = file_get_contents('certificate_with_private_key_and_extra_certs.p12'); $p12_password = 'password'; $sc = new SoapClient('URL to SOAP webservice with HTTPS endpoint'); var_dump($sc->method()); $result = openssl_pkcs12_read($p12, $cert_data, $p12_password); var_dump($sc->method()); //this causes warning and soap exception Expected result: ---------------- <var dumped result of $sc->method()> <var dumped result of $sc->method()> Actual result: -------------- <var dumped result of $sc->method()> Warning: SoapClient::__doRequest(): SSL operation failed with code 1. OpenSSL Error messages: error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch Fatal error: Uncaught SoapFault exception: [HTTP] Error Fetching http headers ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69882&edit=1

« previous php.bugs (#193777) next »