Req #52356 [Asn->Opn]: In memory support for openssl_pkcs7_*
| From: | kalle@php.net | Date: | Tue, 24 Oct 2017 07:32:01 +0000 |
| Subject: | Req #52356 [Asn->Opn]: In memory support for openssl_pkcs7_* | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-212094@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=52356&edit=1
ID: 52356
Updated by: kalle@php.net
Reported by: p dot vanbrouwershaven at networking4all dot com
Summary: In memory support for openssl_pkcs7_*
-Status: Assigned
+Status: Open
Type: Feature/Change Request
Package: OpenSSL related
PHP Version: Irrelevant
-Assigned To: pajoye
+Assigned To:
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2014-01-13 18:33:36] php at kriegt dot es
Added a pull request on github for this:
https://github.com/php/php-src/pull/560
------------------------------------------------------------------------
[2014-01-13 15:10:33] php at kriegt dot es
Since I see no chance to change the current functions (openssl_pkcs7_encrypt/decrypt) to the schema
I would need it, I just added two new functions named:
- openssl_pkcs7_mem_encrypt
- openssl_pkcs7_mem_decrypt
These functions use BIO_s_mem instead of BIO_s_file to create the necessary BIO data handled by the
PKCS7 functions.
I tested this with the following skript and it worked as it should:
<?php
$message = "hey there, this is top secret message which gets encrypted by memory soon";
#$infile = tempnam(sys_get_temp_dir(),'smime');
#$tmpfile = fopen( $infile, 'w+' );
#fwrite($tmpfile,$message,strlen($message));
#echo "Raw Message in $infile\n";
#$outfile = tempnam(sys_get_temp_dir(),'smime');
$certfile = "/path/to/just/the/certificate.pem";
$encrypted = "";
if( openssl_pkcs7_mem_encrypt( $message, $encrypted, file_get_contents($certfile), array() ) ) {
var_dump( $encrypted );
}
$p12key = "/my/path/to/related/p12file.p12"
$password = "mysecretpasswordforkey";
openssl_pkcs12_read(file_get_contents($p12key), $certdata, $password);
$key = $certdata['pkey'];
$cert = $certdata['cert'];
if( strlen($key) != 0 ) {
# echo "Key okay!\n";
}
if( trim($encrypted) != "" ) {
if( openssl_pkcs7_mem_decrypt( $encrypted, $decrypted, $cert, array( $key, $password ) ) ) {
var_dump( $decrypted );
}
}
#################
First var_dump returns encrypted data
Second var_dump returns content of $message
------------------------------------------------------------------------
[2014-01-13 12:23:41] php at kriegt dot es
Hi,
what is the status of this feature request? I really would love to see this in some of the next
versions as I already asked something about that on stackoverflow:
http://stackoverflow.com/questions/21053935/php-openssl-pkcs7-needs-files-security-issue
If you need a free S/Mime certificate for one year for testing purposes, request it on https://www.startssl.com/ for any Mailaddress you want AND OWN
ofcourse (either gmail or hotmail, whatever).
There should be a way to pass the encrypted/unencrypted mail as a string variable, not as a
filename. Since PKCS7_decrypt(3) says that the BIO filehandler could be even memory based.
https://www.openssl.org/docs/crypto/PKCS7_encrypt.html
Please check this out again.
------------------------------------------------------------------------
[2010-07-16 11:00:26] p dot vanbrouwershaven at networking4all dot com
You can download the zipfile here:
https://docs.google.com/leaf?
id=0B3a2D2VoY8NgZGEzZGIxYzQtYWFiNS00NDNkLWI2ZGQtM2Y5YjQwNjM3Yjc2&hl=en&authkey=C
KeKg4cJ
Please request a free 30 day trail client certificate if you don't have one
already for your own. (takes just a minute, the intermediate is already included
in the zipfile)
http://www.globalsign.com/authentication-secure-email/digital-id/trial-
personalsign.html
------------------------------------------------------------------------
[2010-07-16 10:45:24] pajoye@php.net
Can you link to a zip containing what you use for this example please? May help to debug the issue
you are describing while being at it.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=52356
--
Edit this bug report at https://bugs.php.net/bug.php?id=52356&edit=1