Bug #78444 [Opn]: openssl_pkey_new generates OpenSSL errors with OpenSSL 1.1.1
| From: | jmaguire at duo dot com | Date: | Thu, 22 Aug 2019 17:15:39 +0000 |
| Subject: | Bug #78444 [Opn]: openssl_pkey_new generates OpenSSL errors with OpenSSL 1.1.1 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222372@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78444&edit=1
ID: 78444
User updated by: jmaguire at duo dot com
Reported by: jmaguire at duo dot com
Summary: openssl_pkey_new generates OpenSSL errors with
OpenSSL 1.1.1
Status: Open
Type: Bug
Package: OpenSSL related
Operating System: Linux/Windows
PHP Version: 7.3.8
Block user comment: N
Private report: N
New Comment:
I think the preferred resolution would be to not use the RANDFILE at all...
Previous Comments:
------------------------------------------------------------------------
[2019-08-22 16:20:01] jmaguire at duo dot com
I appears that OpenSSL 1.1.1 adds an error to the error queue when calling RAND_load_file when the
file does not exist, while OpenSSL 1.02 does not.
https://gist.github.com/JohnMaguire/d905b3b645c610457e541d27e2462a1d
------------------------------------------------------------------------
[2019-08-22 14:45:31] jmaguire at duo dot com
Looking at the code around here, I find it surprising that neither the return value nor the value of
seeded are checked after calling php_openssl_load_rand_file(): https://github.com/php/php-src/blob/31d7f9763b4825e667eb34437f2bd7fbef5067e6/ext/openssl/openssl.c#L3964-L3968
Has the RNG been seeded in this case?
------------------------------------------------------------------------
[2019-08-22 14:38:53] jmaguire at duo dot com
Description:
------------
If a .rnd file does not exist in the user's directory, openssl_pkey_new will generate an error:
error:2406F079:random number generator:RAND_load_file:Cannot open file
The .rnd file will be created, and the operation appears to work, but this causes issues when trying
to detect errors in the OpenSSL pkey creation.
Subsequent calls to openssl_pkey_new succeed, as the .rnd file is created successfully.
It seems that running, e.g.
openssl genrsa -des3 -out private.pem 2048 at the command
line does not create or need this .rnd file anymore.
Test script:
---------------
<?php
unlink(getenv('HOME') . '/.rnd');
openssl_pkey_new();
while ($err = openssl_error_string()) {
echo $err . PHP_EOL;
}
Expected result:
----------------
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
Actual result:
--------------
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:0E06D06C:configuration file routines:NCONF_get_string:no value
error:2406F079:random number generator:RAND_load_file:Cannot open file
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78444&edit=1