Bug #73478 [NEW]: openssl_pkey_new() generates wrong pub/priv keys with Diffie Hellman
| From: | enrico at zimuel dot it | Date: | Tue, 08 Nov 2016 16:53:46 +0000 |
| Subject: | Bug #73478 [NEW]: openssl_pkey_new() generates wrong pub/priv keys with Diffie Hellman | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-205242@lists.php.net to get a copy of this message | ||
From: enrico at zimuel dot it
Operating system: Ubuntu 16.04
PHP version: 7.1.0RC5
Package: OpenSSL related
Bug Type: Bug
Bug description:openssl_pkey_new() generates wrong pub/priv keys with Diffie Hellman
Description:
------------
I'm testing the zendframework/zend-crypt library using PHP7.1.0RC5 and I
found an issue on openssl_pkey_new() using the Diffie Hellman key
generator. Using the same parameters the output (public and private
keys) is different for each execution.
I tested the test scripts on PHP 7.0.8, 7.0.4, 5.6.20 and it works
fine.
I'm using OpenSSL 1.0.2g 1 Mar 2016.
Test script:
---------------
$details = [
'p' =>
base64_decode('3Pk6C4g5cuwOGZiaxaLOMQ4dN3F+jZVxu3Yjcxhm5h73Wi4niYsFf5iRwuJ6Y5w/KbYIFFgc07LKOYbSaDcFV31FwuflLcgcehcYduXOp0sUSL/frxiCjv0lGfFOReOCZjSvGUnltTXMgppIO4p2Ij5dSQolfwW9/xby+yLFg6s='),
'g' => base64_decode('Ag=='),
'priv_key' =>
base64_decode('jUdcV++P/m7oUodWiqKqKXZVenHRuj92Ig6Fmzs7QlqVdUc5mNBxmEWjug+ObffanPpOeab/LyXwjNMzevtBz3tW4oROau++9EIMJVVQr8fW9zdYBJcYieC5l4t8nRj5/Uu/Z0G2rWVLBleSi28mqqNEvnUs7uxYxrar69lwQYs=')
];
$opensslKeyResource = openssl_pkey_new(['dh' => $details]);
$data = openssl_pkey_get_details($opensslKeyResource);
printf("Private key:\n%s\n", base64_encode($data['dh']['priv_key']));
printf("Public key:\n%s\n", base64_encode($data['dh']['pub_key']));
Expected result:
----------------
Private key:
jUdcV++P/m7oUodWiqKqKXZVenHRuj92Ig6Fmzs7QlqVdUc5mNBxmEWjug+ObffanPpOeab/LyXwjNMzevtBz3tW4oROau++9EIMJVVQr8fW9zdYBJcYieC5l4t8nRj5/Uu/Z0G2rWVLBleSi28mqqNEvnUs7uxYxrar69lwQYs=
Public key:
0DmJUe9dr02pAtVoGyLHdC+rfBU3mDCelKGPXRDFHofx6mFfN2gcZCmp/ab4ezDXfpIBOatpVdbn2fTNUGo64DtKE2WGTsZCl90RgrGUv8XW/4WDPXeE7g5u7KWHBG/LCE5+XsilE5P5/GIyqr9gsiudTmk+H/hiYZl9Smar9k0=
Actual result:
--------------
The output is different for each execution, for instance this is one:
Private key:
fSv1nExIL8OaVzXIpKCw7YA3w9t5onYM9LR9glI2XEXttltLdfi2/l87iMsOeW+7aeNvGg97DtVC6xbiXmz7UrEyn1sLynauxTGF35xRCL2yCiYdbqcwDpzc2Xj31ggRjhZYTdf8BnM2kIUzTwt733+P0bDB0OhkAz07DvKahz4=
Public key:
S2/Lci8eLGt/ayV3faOJGb6daczG0z55VCoy9eHFhDqy6KHcPiPSnaF/GLyG5bhnlNgLeI9eU/yEIR6A8m+6Crd51A08itmmU2A6dhMtjbT8LYSHCQ1RlBcoasfEahhEltNZFErxl8whVPRXBrwDyZKwCmHu+AJYpoSTQFA6y4I=
--
Edit bug report at https://bugs.php.net/bug.php?id=73478&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73478&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73478&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73478&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73478&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73478&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73478&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73478&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73478&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73478&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73478&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73478&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73478&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73478&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73478&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73478&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73478&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73478&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73478&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73478&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73478&r=mysqlcfg