Bug #69882 [Opn->Csd]: OpenSSL error “key values mismatch” after openssl_pkcs12_read with extra cer

From: Date: Thu, 25 Jun 2015 22:04:23 +0000
Subject: Bug #69882 [Opn->Csd]: OpenSSL error “key values mismatch” after openssl_pkcs12_read with extra cer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193891@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69882&edit=1 ID: 69882 Updated by: datibbaw@php.net Reported by: falundir at gmail dot com Summary: OpenSSL error “key values mismatch” after openssl_pkcs12_read with extra cer -Status: Open +Status: Closed Type: Bug Package: OpenSSL related Operating System: Debian 8.0 PHP Version: 5.6.7 Block user comment: N Private report: N New Comment: Automatic comment on behalf of datibbaw Revision: http://git.php.net/?p=php-src.git;a=commit;h=2ff3dafccfa4fd0bc031d5165f84593d092148d2 Log: Fixed #69882: OpenSSL error "key values mismatch" after openssl_pkcs12_read with extra certs Previous Comments: ------------------------------------------------------------------------ [2015-06-24 10:00:34] falundir at gmail dot com The workaround is to call openssl_error_string() after openssl_pkcs12_read(). ------------------------------------------------------------------------ [2015-06-23 09:42:02] falundir at gmail dot com Reported as bug in OpenSSL: https://rt.openssl.org/Ticket/Display.html?id=3923 ------------------------------------------------------------------------ [2015-06-23 08:28:14] falundir at gmail dot com Changed summary to properly reflect source of problem. ------------------------------------------------------------------------ [2015-06-23 07:09:17] falundir at gmail dot com The "key values mismatch" is triggered in openssl_pkcs12_read by PKCS12_parse, because it uses X509_check_private_key to separate main certificate (which corresponds to private key) from extra certificates. Extra certificates usually comes first (p12 contents are reversed as stack) and X509_check_private_key triggers X509_R_KEY_VALUES_MISMATCH error. I guess, the fix will be to pop any X509_R_KEY_VALUES_MISMATCH errors when there are extra certificates. Will try that. ------------------------------------------------------------------------ [2015-06-22 19:48:08] falundir at gmail dot com I have been able to "fix" this error by calling ERR_get_error() at the cleanup section of openssl_pkcs12_read method. Something in there is producing this "key values mismatch" error and since it's not consumed in this method, it is picked up by php_openssl_sockop_io. Change in this commit introduced a line: int err = SSL_get_error(sslsock->ssl_handle, nr_bytes ); before: retry = handle_ssl_error(stream, nr_bytes, 0 TSRMLS_CC); which effectively cleared SSL error from handle_ssl_error and made handle_ssl_error go to default section of switch where ERR_get_error() is handled. If this change is OK or not is another case, but primary case would be to check what is producing "key values mismatch" error at openssl_pkcs12_read and handle it there properly. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69882 -- Edit this bug report at https://bugs.php.net/bug.php?id=69882&edit=1

« previous php.bugs (#193891) next »