Bug #77416 [NEW]: openssl_csr_new add fields to subject

From: Date: Sun, 06 Jan 2019 19:22:46 +0000
Subject: Bug #77416 [NEW]: openssl_csr_new add fields to subject
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218812@lists.php.net to get a copy of this message
From:             joose dot vettenranta at kompassi dot fi
Operating system: Linux
PHP version:      7.2.13
Package:          OpenSSL related
Bug Type:         Bug
Bug description:openssl_csr_new  add fields to subject

Description:
------------
When creating new CSR, it will add "ST=Some-State, O=Internet Widgits
Pty Ltd" to the subject if not defined in openssl_csr_new -function
call. This has been a bug in PHP for a long time.

Test script:
---------------
<?php
$config=array(
    "private_key_bits" => 2048,
    "private_key_type" => OPENSSL_KEYTYPE_RSA,
);
$privkey = openssl_pkey_new($config);

$csr = openssl_csr_new(array("C"=>"FI"), $privkey);

openssl_csr_export($csr, $csrout);
echo($csrout);

/* using same system, but command line openssl command to generate csr
works just fine. I have been using this code to do csr:
 $csr = shell_exec('openssl req -new -sha256 -key
'.$tempDir.'/private.key -outform '.$format.' -subj
"'.$subject.'"');
*/
?>
$ php test.php > /tmp/foo3 
$ openssl req -in /tmp/foo3 -noout -text


Expected result:
----------------
Certificate Request:
    Data:
    Version: 0 (0x0)
    Subject: C=FI

Actual result:
--------------
Certificate Request:
    Data:
    Version: 0 (0x0)
    Subject: C=FI, ST=Some-State, O=Internet Widgits Pty Ltd


-- 
Edit bug report at https://bugs.php.net/bug.php?id=77416&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=77416&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=77416&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=77416&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=77416&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=77416&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=77416&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=77416&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=77416&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=77416&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=77416&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=77416&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=77416&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=77416&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77416&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=77416&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=77416&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=77416&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77416&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=77416&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=77416&r=mysqlcfg



Thread (7 messages)

« previous php.bugs (#218812) next »