Bug #74335 [Csd->Nab]: digest_alg configarg for openssl_csr_sign has no effect

From: Date: Wed, 29 Mar 2017 16:02:05 +0000
Subject: Bug #74335 [Csd->Nab]: digest_alg configarg for openssl_csr_sign has no effect
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208159@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74335&edit=1 ID: 74335 Updated by: daverandom@php.net Reported by: jmaguire at duo dot com Summary: digest_alg configarg for openssl_csr_sign has no effect -Status: Closed +Status: Not a bug Type: Bug Package: OpenSSL related Operating System: Linux PHP Version: 7.1.3 Block user comment: N Private report: N New Comment: Additional example info showing the effects of these values <?php $privKey = openssl_pkey_new(); $csr = openssl_csr_new([ 'countryName' => 'US', 'stateOrProvinceName' => 'MI', 'localityName' => 'Ann Arbor', 'organizationName' => 'Duo', 'commonName' => 'localhost', 'emailAddress' => 'jmaguire@duo.com' ], $privKey, ['digest_alg' => 'sha256']); openssl_csr_export($csr, $contents); file_put_contents('req.csr', $contents); $ssCert = openssl_csr_sign($csr, null, $privKey, 30, ['digest_alg' => 'sha256']); openssl_pkey_export($privKey, $contents); file_put_contents('private.key', $contents); openssl_x509_export($ssCert, $contents); file_put_contents('public.crt', $contents); ?> #> openssl req -noout -text -in req.csr Certificate Request: Data: Version: 0 (0x0) Subject: C=US, ST=MI, L=Ann Arbor, O=Duo, CN=localhost/emailAddress=jmaguire@duo.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (1024 bit) Modulus: 00:e5:37:b6:2d:ce:9b:63:8d:e8:db:0f:54:ba:53: c8:67:38:d9:cf:cc:aa:ad:93:c0:a5:aa:8e:ac:d9: 11:c9:05:45:e5:9e:66:8c:ac:0e:17:06:48:43:ba: 4d:3a:ee:08:ea:e2:70:33:1c:8d:92:94:c9:9d:08: 72:e9:54:bd:f1:f7:20:a4:4b:f9:99:04:b3:96:c0: 19:bd:a2:65:24:e5:1a:e8:b5:c7:a6:33:06:a8:bc: fc:a4:b7:7a:3f:c7:99:d5:7c:0e:45:a0:2f:c4:cf: 19:1f:f9:31:9f:ed:e3:1b:10:f0:9b:22:c4:14:d2: 35:b5:2e:8f:c3:67:b9:eb:47 Exponent: 65537 (0x10001) Attributes: a0:00 Signature Algorithm: sha256WithRSAEncryption 5e:b4:03:7a:d2:71:8f:fe:bf:b0:9d:90:2a:77:60:c8:33:5b: c6:8e:0a:b4:b0:5e:77:29:57:8c:d6:3c:2e:c8:ce:53:da:fc: e2:2e:a4:ab:ac:e7:99:0f:63:45:94:0f:dd:42:ad:e7:f1:62: a9:42:cf:8a:51:0a:cb:e5:e3:67:b4:4d:1d:16:8b:f9:f2:5e: 2f:13:50:1e:7a:d1:50:9f:07:97:aa:95:4a:8a:11:23:92:32: 2f:05:49:4f:2b:22:72:55:7c:2c:a6:66:d6:a9:22:64:9f:6d: 35:fb:82:ab:54:91:9d:8f:e6:88:39:75:51:cc:a2:82:03:9d: f9:b4 #> openssl x509 -noout -text -in public.crt Certificate: Data: Version: 3 (0x2) Serial Number: 0 (0x0) Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=MI, L=Ann Arbor, O=Duo, CN=localhost/emailAddress=jmaguire@duo.com Validity Not Before: Mar 29 15:57:03 2017 GMT Not After : Apr 28 15:57:03 2017 GMT Subject: C=US, ST=MI, L=Ann Arbor, O=Duo, CN=localhost/emailAddress=jmaguire@duo.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (1024 bit) Modulus: 00:e5:37:b6:2d:ce:9b:63:8d:e8:db:0f:54:ba:53: c8:67:38:d9:cf:cc:aa:ad:93:c0:a5:aa:8e:ac:d9: 11:c9:05:45:e5:9e:66:8c:ac:0e:17:06:48:43:ba: 4d:3a:ee:08:ea:e2:70:33:1c:8d:92:94:c9:9d:08: 72:e9:54:bd:f1:f7:20:a4:4b:f9:99:04:b3:96:c0: 19:bd:a2:65:24:e5:1a:e8:b5:c7:a6:33:06:a8:bc: fc:a4:b7:7a:3f:c7:99:d5:7c:0e:45:a0:2f:c4:cf: 19:1f:f9:31:9f:ed:e3:1b:10:f0:9b:22:c4:14:d2: 35:b5:2e:8f:c3:67:b9:eb:47 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 35:0B:CA:D4:E6:2C:02:BC:3E:65:13:EB:F8:07:DB:F0:E9:FE:52:A6 X509v3 Authority Key Identifier: keyid:35:0B:CA:D4:E6:2C:02:BC:3E:65:13:EB:F8:07:DB:F0:E9:FE:52:A6 DirName:/C=US/ST=MI/L=Ann Arbor/O=Duo/CN=localhost/emailAddress=jmaguire@duo.com serial:00 X509v3 Basic Constraints: CA:TRUE Signature Algorithm: sha256WithRSAEncryption d7:8c:8b:83:0e:2a:85:7e:ed:2d:7e:39:36:62:43:16:d0:da: 75:b0:0d:bb:18:7a:d5:8c:a6:70:79:37:0c:22:b5:7c:3a:45: fe:45:b0:13:27:5e:07:3f:6b:e2:36:81:30:28:18:e2:e4:b4: e7:88:7a:a3:9d:a8:ff:07:44:f4:45:de:75:1d:42:74:58:5d: d2:0f:f0:4a:72:83:17:39:28:4d:4c:05:ec:0c:17:05:07:80: 91:2d:67:a4:cf:ca:f2:49:35:3b:1a:1b:4b:6b:12:60:fd:b6: aa:ea:bf:da:7b:1b:c4:0b:90:78:33:57:e9:fc:df:49:89:ab: 58:52 Previous Comments: ------------------------------------------------------------------------ [2017-03-29 15:59:25] jmaguire at duo dot com Sorry for the foolishness, and thanks all for the help. ------------------------------------------------------------------------ [2017-03-29 15:56:53] kelunik@php.net Your bug title says "openssl_csr_sign" doesn't obey "digest_alg", but you pass "digest_alg" to "openssl_csr_new" instead. It works fine if you pass the option to "openssl_csr_sign". Unfortunately, the documentation just mentions all options for each and every function, while only some apply to each. ------------------------------------------------------------------------ [2017-03-29 15:53:32] daverandom@php.net https://security.stackexchange.com/a/67235/41073 tl;dr specifying digest_alg at openssl_csr_new() does not specify what should be used when signing the certificate, rather what should be used when signing the CSR itself. Props to leigh for finding this. ------------------------------------------------------------------------ [2017-03-29 15:45:28] daverandom@php.net Thinking about it I'm not sure it actually makes sense to specify the algorithm at the point of creating a new CSR, surely that's up to the signing CA to determine? When exported, a CSR does not (afaik?) contain this information, so logically it doesn't make sense to specify it here. If what I said there ^ is correct (it may not be), I think this is a documentation issue more than anything else. ------------------------------------------------------------------------ [2017-03-29 15:37:21] daverandom@php.net The issue is that openssl_csr_sign() is not using the value defined in the CSR created with openssl_csr_new(). If you pass the ['digest_alg' => 'whatever'] config arg directly to openssl_csr_sign() then it works as expected. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74335 -- Edit this bug report at https://bugs.php.net/bug.php?id=74335&edit=1

« previous php.bugs (#208159) next »