Bug #73478 [NEW]: openssl_pkey_new() generates wrong pub/priv keys with Diffie Hellman

From: Date: Tue, 08 Nov 2016 16:53:46 +0000
Subject: Bug #73478 [NEW]: openssl_pkey_new() generates wrong pub/priv keys with Diffie Hellman
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205242@lists.php.net to get a copy of this message
From: enrico at zimuel dot it Operating system: Ubuntu 16.04 PHP version: 7.1.0RC5 Package: OpenSSL related Bug Type: Bug Bug description:openssl_pkey_new() generates wrong pub/priv keys with Diffie Hellman Description: ------------ I'm testing the zendframework/zend-crypt library using PHP7.1.0RC5 and I found an issue on openssl_pkey_new() using the Diffie Hellman key generator. Using the same parameters the output (public and private keys) is different for each execution. I tested the test scripts on PHP 7.0.8, 7.0.4, 5.6.20 and it works fine. I'm using OpenSSL 1.0.2g 1 Mar 2016. Test script: --------------- $details = [ 'p' => base64_decode('3Pk6C4g5cuwOGZiaxaLOMQ4dN3F+jZVxu3Yjcxhm5h73Wi4niYsFf5iRwuJ6Y5w/KbYIFFgc07LKOYbSaDcFV31FwuflLcgcehcYduXOp0sUSL/frxiCjv0lGfFOReOCZjSvGUnltTXMgppIO4p2Ij5dSQolfwW9/xby+yLFg6s='), 'g' => base64_decode('Ag=='), 'priv_key' => base64_decode('jUdcV++P/m7oUodWiqKqKXZVenHRuj92Ig6Fmzs7QlqVdUc5mNBxmEWjug+ObffanPpOeab/LyXwjNMzevtBz3tW4oROau++9EIMJVVQr8fW9zdYBJcYieC5l4t8nRj5/Uu/Z0G2rWVLBleSi28mqqNEvnUs7uxYxrar69lwQYs=') ]; $opensslKeyResource = openssl_pkey_new(['dh' => $details]); $data = openssl_pkey_get_details($opensslKeyResource); printf("Private key:\n%s\n", base64_encode($data['dh']['priv_key'])); printf("Public key:\n%s\n", base64_encode($data['dh']['pub_key'])); Expected result: ---------------- Private key: jUdcV++P/m7oUodWiqKqKXZVenHRuj92Ig6Fmzs7QlqVdUc5mNBxmEWjug+ObffanPpOeab/LyXwjNMzevtBz3tW4oROau++9EIMJVVQr8fW9zdYBJcYieC5l4t8nRj5/Uu/Z0G2rWVLBleSi28mqqNEvnUs7uxYxrar69lwQYs= Public key: 0DmJUe9dr02pAtVoGyLHdC+rfBU3mDCelKGPXRDFHofx6mFfN2gcZCmp/ab4ezDXfpIBOatpVdbn2fTNUGo64DtKE2WGTsZCl90RgrGUv8XW/4WDPXeE7g5u7KWHBG/LCE5+XsilE5P5/GIyqr9gsiudTmk+H/hiYZl9Smar9k0= Actual result: -------------- The output is different for each execution, for instance this is one: Private key: fSv1nExIL8OaVzXIpKCw7YA3w9t5onYM9LR9glI2XEXttltLdfi2/l87iMsOeW+7aeNvGg97DtVC6xbiXmz7UrEyn1sLynauxTGF35xRCL2yCiYdbqcwDpzc2Xj31ggRjhZYTdf8BnM2kIUzTwt733+P0bDB0OhkAz07DvKahz4= Public key: S2/Lci8eLGt/ayV3faOJGb6daczG0z55VCoy9eHFhDqy6KHcPiPSnaF/GLyG5bhnlNgLeI9eU/yEIR6A8m+6Crd51A08itmmU2A6dhMtjbT8LYSHCQ1RlBcoasfEahhEltNZFErxl8whVPRXBrwDyZKwCmHu+AJYpoSTQFA6y4I= -- Edit bug report at https://bugs.php.net/bug.php?id=73478&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73478&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73478&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73478&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73478&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73478&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73478&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73478&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73478&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73478&r=support Expected behavior: https://bugs.php.net/fix.php?id=73478&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73478&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73478&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73478&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73478&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73478&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73478&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73478&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73478&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73478&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73478&r=mysqlcfg

« previous php.bugs (#205242) next »