Bug #73833 [Asn->Csd]: null character not allowed in openssl_pkey_get_private

From: Date: Mon, 24 Apr 2017 16:11:56 +0000
Subject: Bug #73833 [Asn->Csd]: null character not allowed in openssl_pkey_get_private
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208751@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73833&edit=1

 ID:                 73833
 Updated by:         bukka@php.net
 Reported by:        mfaust at usinternet dot com
 Summary:            null character not allowed in
                     openssl_pkey_get_private
-Status:             Assigned
+Status:             Closed
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Linux
 PHP Version:        5.6.29
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=9fa347997a47d5b44515a701b695e47696cba04b
Log: Fix bug #73833 (null character not allowed in openssl_pkey_get_private)


Previous Comments:
------------------------------------------------------------------------
[2016-12-29 15:34:05] mfaust at usinternet dot com

missing trailing }, sorry.

------------------------------------------------------------------------
[2016-12-29 15:33:27] mfaust at usinternet dot com

Description:
------------
When encrypting a private key for export you are allowed to have a null character as part of the
password key, but when decrypting with openssl_pkey_get_private it fails to decrypt with the same
key.

PHP is compiled against OpenSSL 1.0.1e-fips 11 Feb 2013

Test script:
---------------
//This will fail to decrypt using the first password due to the null byte (\x00)
$passwords = ["abc\x00defghijkl", "abcdefghikjl"];

foreach($passwords as $password){
    $key = openssl_pkey_new();

    if(openssl_pkey_export($key, $privatePEM, $password) === FALSE){
        echo "Failed to encrypt.\n";
    }else{
        echo "Encrypted!\n";
    }

    //This will throw a warning and fail to decrypt.
    if(openssl_pkey_get_private($privatePEM, $password) === FALSE){
        echo "Failed to decrypt.\n";
    }else{
        echo "Decrypted!\n";
    }



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73833&edit=1


Thread (4 messages)

« previous php.bugs (#208751) next »