Bug #74291 [Opn->Csd]: openssl_pkcs12_read only returns 1 extracert when the .pfx has multiples
| From: | ab@php.net | Date: | Thu, 25 May 2017 19:31:37 +0000 |
| Subject: | Bug #74291 [Opn->Csd]: openssl_pkcs12_read only returns 1 extracert when the .pfx has multiples | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-209261@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74291&edit=1
ID: 74291
Updated by: ab@php.net
Reported by: always666 at gmail dot com
Summary: openssl_pkcs12_read only returns 1 extracert when
the .pfx has multiples
-Status: Open
+Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: irrelevant
PHP Version: 7.0.17
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Fixed with 464c1639ae544e3952823caf169d2e4199a32fc3.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2017-03-22 14:27:18] always666 at gmail dot com
Description:
------------
latest Fix "#74022 PHP Fast CGI crashes when reading from a pfx file."
broke the export of multiple extracerts.
in git source control theres a bad loop in line 2667
for (i=0; i < sk_X509_num(ca); i++) {
cause in line 2669
X509* aCA = sk_X509_pop(ca);
will return and remove the last element from ca so the loop will only iterate once.
The correct code should be the previous:
for (i=0;;i++) {
cause the theres already checks in place to evaluate if the there is no more certs to process in
line 2670:
if (!aCA) break;
link to git revision for beter understanding.
https://github.com/php/php-src/commit/6fc0ae638acd2a66a4181078f4ac5d789762d9de#diff-69bad938d17f4283faa5f7fea17fa627
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74291&edit=1