Bug #73833 [Opn->Asn]: null character not allowed in openssl_pkey_get_private
| From: | bukka@php.net | Date: | Mon, 24 Apr 2017 16:01:59 +0000 |
| Subject: | Bug #73833 [Opn->Asn]: null character not allowed in openssl_pkey_get_private | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-208749@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73833&edit=1
ID: 73833
Updated by: bukka@php.net
Reported by: mfaust at usinternet dot com
Summary: null character not allowed in
openssl_pkey_get_private
-Status: Open
+Status: Assigned
Type: Bug
Package: OpenSSL related
Operating System: Linux
PHP Version: 5.6.29
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-12-29 15:34:05] mfaust at usinternet dot com
missing trailing }, sorry.
------------------------------------------------------------------------
[2016-12-29 15:33:27] mfaust at usinternet dot com
Description:
------------
When encrypting a private key for export you are allowed to have a null character as part of the
password key, but when decrypting with openssl_pkey_get_private it fails to decrypt with the same
key.
PHP is compiled against OpenSSL 1.0.1e-fips 11 Feb 2013
Test script:
---------------
//This will fail to decrypt using the first password due to the null byte (\x00)
$passwords = ["abc\x00defghijkl", "abcdefghikjl"];
foreach($passwords as $password){
$key = openssl_pkey_new();
if(openssl_pkey_export($key, $privatePEM, $password) === FALSE){
echo "Failed to encrypt.\n";
}else{
echo "Encrypted!\n";
}
//This will throw a warning and fail to decrypt.
if(openssl_pkey_get_private($privatePEM, $password) === FALSE){
echo "Failed to decrypt.\n";
}else{
echo "Decrypted!\n";
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73833&edit=1