Bug #78444 [Opn]: openssl_pkey_new generates OpenSSL errors with OpenSSL 1.1.1

From: Date: Thu, 22 Aug 2019 17:15:39 +0000
Subject: Bug #78444 [Opn]: openssl_pkey_new generates OpenSSL errors with OpenSSL 1.1.1
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222372@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78444&edit=1 ID: 78444 User updated by: jmaguire at duo dot com Reported by: jmaguire at duo dot com Summary: openssl_pkey_new generates OpenSSL errors with OpenSSL 1.1.1 Status: Open Type: Bug Package: OpenSSL related Operating System: Linux/Windows PHP Version: 7.3.8 Block user comment: N Private report: N New Comment: I think the preferred resolution would be to not use the RANDFILE at all... Previous Comments: ------------------------------------------------------------------------ [2019-08-22 16:20:01] jmaguire at duo dot com I appears that OpenSSL 1.1.1 adds an error to the error queue when calling RAND_load_file when the file does not exist, while OpenSSL 1.02 does not. https://gist.github.com/JohnMaguire/d905b3b645c610457e541d27e2462a1d ------------------------------------------------------------------------ [2019-08-22 14:45:31] jmaguire at duo dot com Looking at the code around here, I find it surprising that neither the return value nor the value of seeded are checked after calling php_openssl_load_rand_file(): https://github.com/php/php-src/blob/31d7f9763b4825e667eb34437f2bd7fbef5067e6/ext/openssl/openssl.c#L3964-L3968 Has the RNG been seeded in this case? ------------------------------------------------------------------------ [2019-08-22 14:38:53] jmaguire at duo dot com Description: ------------ If a .rnd file does not exist in the user's directory, openssl_pkey_new will generate an error: error:2406F079:random number generator:RAND_load_file:Cannot open file The .rnd file will be created, and the operation appears to work, but this causes issues when trying to detect errors in the OpenSSL pkey creation. Subsequent calls to openssl_pkey_new succeed, as the .rnd file is created successfully. It seems that running, e.g. openssl genrsa -des3 -out private.pem 2048 at the command line does not create or need this .rnd file anymore. Test script: --------------- <?php unlink(getenv('HOME') . '/.rnd'); openssl_pkey_new(); while ($err = openssl_error_string()) { echo $err . PHP_EOL; } Expected result: ---------------- error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value Actual result: -------------- error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:2406F079:random number generator:RAND_load_file:Cannot open file ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78444&edit=1

« previous php.bugs (#222372) next »