Bug #78444 [Opn]: openssl_pkey_new generates OpenSSL errors with OpenSSL 1.1.1

From: Date: Sun, 20 Oct 2019 16:54:16 +0000
Subject: Bug #78444 [Opn]: openssl_pkey_new generates OpenSSL errors with OpenSSL 1.1.1
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223343@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78444&edit=1 ID: 78444 Updated by: bukka@php.net Reported by: jmaguire at duo dot com Summary: openssl_pkey_new generates OpenSSL errors with OpenSSL 1.1.1 Status: Open Type: Bug Package: OpenSSL related Operating System: Linux/Windows PHP Version: 7.3.8 Block user comment: N Private report: N New Comment: Yeah I guess it probably doesn't make much sense to use RAND_load_file as PHP is not usually run on the low entropy systems. I guess we could also use stat but I don't see this as a big priority to be honest. The error strings from OpenSSL are not part of BC and one shouldn't really relay on their order when updating OpenSSL. Previous Comments: ------------------------------------------------------------------------ [2019-08-22 17:15:39] jmaguire at duo dot com I think the preferred resolution would be to not use the RANDFILE at all... ------------------------------------------------------------------------ [2019-08-22 16:20:01] jmaguire at duo dot com I appears that OpenSSL 1.1.1 adds an error to the error queue when calling RAND_load_file when the file does not exist, while OpenSSL 1.02 does not. https://gist.github.com/JohnMaguire/d905b3b645c610457e541d27e2462a1d ------------------------------------------------------------------------ [2019-08-22 14:45:31] jmaguire at duo dot com Looking at the code around here, I find it surprising that neither the return value nor the value of seeded are checked after calling php_openssl_load_rand_file(): https://github.com/php/php-src/blob/31d7f9763b4825e667eb34437f2bd7fbef5067e6/ext/openssl/openssl.c#L3964-L3968 Has the RNG been seeded in this case? ------------------------------------------------------------------------ [2019-08-22 14:38:53] jmaguire at duo dot com Description: ------------ If a .rnd file does not exist in the user's directory, openssl_pkey_new will generate an error: error:2406F079:random number generator:RAND_load_file:Cannot open file The .rnd file will be created, and the operation appears to work, but this causes issues when trying to detect errors in the OpenSSL pkey creation. Subsequent calls to openssl_pkey_new succeed, as the .rnd file is created successfully. It seems that running, e.g. openssl genrsa -des3 -out private.pem 2048 at the command line does not create or need this .rnd file anymore. Test script: --------------- <?php unlink(getenv('HOME') . '/.rnd'); openssl_pkey_new(); while ($err = openssl_error_string()) { echo $err . PHP_EOL; } Expected result: ---------------- error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value Actual result: -------------- error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:0E06D06C:configuration file routines:NCONF_get_string:no value error:2406F079:random number generator:RAND_load_file:Cannot open file ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78444&edit=1

« previous php.bugs (#223343) next »