Bug #74700 [Opn->Nab]: Faulty returned values openssl_pkey_get_details

From: Date: Sun, 11 Jun 2017 16:49:35 +0000
Subject: Bug #74700 [Opn->Nab]: Faulty returned values openssl_pkey_get_details
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209482@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74700&edit=1 ID: 74700 Updated by: bukka@php.net Reported by: nothingam at protonmail dot com Summary: Faulty returned values openssl_pkey_get_details -Status: Open +Status: Not a bug Type: Bug Package: OpenSSL related Operating System: Debian PHP Version: 5.6.30 -Assigned To: +Assigned To: bukka Block user comment: N Private report: N New Comment: This is expected and it's what we get from BN_bin2bn. Just to correct you, it won't happen for the last byte but the first byte. Previous Comments: ------------------------------------------------------------------------ [2017-06-06 09:53:31] nothingam at protonmail dot com Description: ------------ The 'openssl_pkey_get_details' function for OPENSSL_KEYTYPE_DH typed keys seems to return faulty 'pub_key's (probably 'priv_key's too). If the last byte is zero byte (0x00), the returned value in the $ret['dh']['pub_key'] is shorter than expected (obviously with one byte in this case). I've successfully reproduced the problem on: - Windows: PHP 5.5.12 (cli) (built: Apr 30 2014 11:20:58) - Debian: PHP 5.6.30-0+deb8u1 (cli) (built: Feb 8 2017 08:50:21) --- From manual page: http://www.php.net/function.openssl-pkey-get-details --- Test script: --------------- $DH_DEFAULT_PRIME = "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD129024E088A67CC74020BBEA63B139B22514A08798E3404DDEF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7EDEE386BFB5A899FA5AE9F24117C4B1FE649286651ECE65381FFFFFFFFFFFFFFFF"; $DH_DEFAULT_GENERATOR = '02'; for($i=0; $i < 500; $i++) { $details = array(); $details['p'] = pack('H*', $DH_DEFAULT_PRIME); $details['g'] = pack('H*', $DH_DEFAULT_GENERATOR); $res = openssl_pkey_new(array("dh" => $details)); $details = openssl_pkey_get_details($res); $privateKey = $details['dh']['priv_key']; $publicKey = $details['dh']['pub_key']; if (strlen($publicKey) != $details['bits']/8) { echo "Whooaa!"; } } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74700&edit=1

« previous php.bugs (#209482) next »