Bug #74700 [Opn->Nab]: Faulty returned values openssl_pkey_get_details
| From: | bukka@php.net | Date: | Sun, 11 Jun 2017 16:49:35 +0000 |
| Subject: | Bug #74700 [Opn->Nab]: Faulty returned values openssl_pkey_get_details | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-209482@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74700&edit=1
ID: 74700
Updated by: bukka@php.net
Reported by: nothingam at protonmail dot com
Summary: Faulty returned values openssl_pkey_get_details
-Status: Open
+Status: Not a bug
Type: Bug
Package: OpenSSL related
Operating System: Debian
PHP Version: 5.6.30
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
This is expected and it's what we get from BN_bin2bn. Just to correct you, it won't happen
for the last byte but the first byte.
Previous Comments:
------------------------------------------------------------------------
[2017-06-06 09:53:31] nothingam at protonmail dot com
Description:
------------
The 'openssl_pkey_get_details' function for OPENSSL_KEYTYPE_DH typed keys seems to return
faulty 'pub_key's (probably 'priv_key's too).
If the last byte is zero byte (0x00), the returned value in the
$ret['dh']['pub_key'] is shorter than expected (obviously with one byte in this
case).
I've successfully reproduced the problem on:
- Windows: PHP 5.5.12 (cli) (built: Apr 30 2014 11:20:58)
- Debian: PHP 5.6.30-0+deb8u1 (cli) (built: Feb 8 2017 08:50:21)
---
From manual page: http://www.php.net/function.openssl-pkey-get-details
---
Test script:
---------------
$DH_DEFAULT_PRIME =
"FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD129024E088A67CC74020BBEA63B139B22514A08798E3404DDEF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7EDEE386BFB5A899FA5AE9F24117C4B1FE649286651ECE65381FFFFFFFFFFFFFFFF";
$DH_DEFAULT_GENERATOR = '02';
for($i=0; $i < 500; $i++) {
$details = array();
$details['p'] = pack('H*', $DH_DEFAULT_PRIME);
$details['g'] = pack('H*', $DH_DEFAULT_GENERATOR);
$res = openssl_pkey_new(array("dh" => $details));
$details = openssl_pkey_get_details($res);
$privateKey = $details['dh']['priv_key'];
$publicKey = $details['dh']['pub_key'];
if (strlen($publicKey) != $details['bits']/8) {
echo "Whooaa!";
}
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74700&edit=1