Bug #73833 [Opn->Asn]: null character not allowed in openssl_pkey_get_private

From: Date: Mon, 24 Apr 2017 16:01:59 +0000
Subject: Bug #73833 [Opn->Asn]: null character not allowed in openssl_pkey_get_private
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208749@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73833&edit=1 ID: 73833 Updated by: bukka@php.net Reported by: mfaust at usinternet dot com Summary: null character not allowed in openssl_pkey_get_private -Status: Open +Status: Assigned Type: Bug Package: OpenSSL related Operating System: Linux PHP Version: 5.6.29 -Assigned To: +Assigned To: bukka Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-12-29 15:34:05] mfaust at usinternet dot com missing trailing }, sorry. ------------------------------------------------------------------------ [2016-12-29 15:33:27] mfaust at usinternet dot com Description: ------------ When encrypting a private key for export you are allowed to have a null character as part of the password key, but when decrypting with openssl_pkey_get_private it fails to decrypt with the same key. PHP is compiled against OpenSSL 1.0.1e-fips 11 Feb 2013 Test script: --------------- //This will fail to decrypt using the first password due to the null byte (\x00) $passwords = ["abc\x00defghijkl", "abcdefghikjl"]; foreach($passwords as $password){ $key = openssl_pkey_new(); if(openssl_pkey_export($key, $privatePEM, $password) === FALSE){ echo "Failed to encrypt.\n"; }else{ echo "Encrypted!\n"; } //This will throw a warning and fail to decrypt. if(openssl_pkey_get_private($privatePEM, $password) === FALSE){ echo "Failed to decrypt.\n"; }else{ echo "Decrypted!\n"; } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73833&edit=1

« previous php.bugs (#208749) next »