Bug #69882 [Opn]: OpenSSL error “key values mismatch” after openssl_pkcs12_read with extra cer

From: Date: Tue, 23 Jun 2015 09:42:02 +0000
Subject: Bug #69882 [Opn]: OpenSSL error “key values mismatch” after openssl_pkcs12_read with extra cer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193789@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69882&edit=1

 ID:                 69882
 User updated by:    falundir at gmail dot com
 Reported by:        falundir at gmail dot com
 Summary:            OpenSSL error “key values mismatch” after
                     openssl_pkcs12_read with extra cer
 Status:             Open
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Debian 8.0
 PHP Version:        5.6.7
 Block user comment: N
 Private report:     N

 New Comment:

Reported as bug in OpenSSL:
https://rt.openssl.org/Ticket/Display.html?id=3923


Previous Comments:
------------------------------------------------------------------------
[2015-06-23 08:28:14] falundir at gmail dot com

Changed summary to properly reflect source of problem.

------------------------------------------------------------------------
[2015-06-23 07:09:17] falundir at gmail dot com

The "key values mismatch" is triggered in openssl_pkcs12_read by PKCS12_parse, because it
uses X509_check_private_key to separate main certificate (which corresponds to private key) from
extra certificates. Extra certificates usually comes first (p12 contents are reversed as stack) and
X509_check_private_key triggers X509_R_KEY_VALUES_MISMATCH error.
I guess, the fix will be to pop any X509_R_KEY_VALUES_MISMATCH errors when there are extra
certificates. Will try that.

------------------------------------------------------------------------
[2015-06-22 19:48:08] falundir at gmail dot com

I have been able to "fix" this error by calling ERR_get_error() at the cleanup section of
openssl_pkcs12_read method. Something in there is producing this "key values mismatch"
error and since it's not consumed in this method, it is picked up by php_openssl_sockop_io.
Change in this commit introduced a line:
int err = SSL_get_error(sslsock->ssl_handle, nr_bytes );
before:
retry = handle_ssl_error(stream, nr_bytes, 0 TSRMLS_CC);
which effectively cleared SSL error from handle_ssl_error and made handle_ssl_error go to default
section of switch where ERR_get_error() is handled.

If this change is OK or not is another case, but primary case would be to check what is producing
"key values mismatch" error at openssl_pkcs12_read and handle it there properly.

------------------------------------------------------------------------
[2015-06-22 08:49:18] falundir at gmail dot com

I've located the specific commit which indroduced the bug:
fd4641696cc67fedf494717b5e4d452019f04d6f (together with next
1482ed2d5660c3875add40706a18fe29e2b3ff70).

------------------------------------------------------------------------
[2015-06-21 20:16:58] falundir at gmail dot com

Verified that PHP 5.6.7 is the first version with this bug. Tested by compiling from the source, so
it's not a problem in Debian packaged version.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69882


--
Edit this bug report at https://bugs.php.net/bug.php?id=69882&edit=1


Thread (11 messages)

« previous php.bugs (#193789) next »