Bug #77416 [Opn]: openssl_csr_new add fields to subject

From: Date: Sun, 01 Dec 2019 19:39:05 +0000
Subject: Bug #77416 [Opn]: openssl_csr_new add fields to subject
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223992@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77416&edit=1

 ID:                 77416
 Updated by:         bukka@php.net
 Reported by:        joose dot vettenranta at kompassi dot fi
 Summary:            openssl_csr_new  add fields to subject
 Status:             Open
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Linux
 PHP Version:        7.2.13
 Block user comment: N
 Private report:     N

 New Comment:

PHP is using default openssl config which is usually the system one but depends on the installation.
This can be overwritten using OPENSSL_CONF environment variable. The default config is always loaded
which is on purpose and it can't be changed due to BC.

So the only solution in here is to either change your default config or use specific config for
openssl_csr_new.


Previous Comments:
------------------------------------------------------------------------
[2019-01-06 21:30:56] joose dot vettenranta at kompassi dot fi

If I create own openssl.cnf file containing: 
distinguished_name  = req_distinguished_name
[req_distinguished_name]
[v3_req]
[v3_ca]

it will work as expected

------------------------------------------------------------------------
[2019-01-06 21:12:44] joose dot vettenranta at kompassi dot fi

I need different kind of subjects when I am creating certificates for systems other than SSL. That
is why to subject is completely different what is normally (SSL) used.

------------------------------------------------------------------------
[2019-01-06 21:09:37] joose dot vettenranta at kompassi dot fi

I have not checked. But I have tried this with different distros, different php -versions and with
different operating systems (macos and linux). Also have tried docker images. And as I notided in
the test script, doing the same thing on the same computer using command line openssl command, it
will work as expected.

------------------------------------------------------------------------
[2019-01-06 19:27:25] requinix@php.net

How does your openssl.cnf look?

------------------------------------------------------------------------
[2019-01-06 19:22:45] joose dot vettenranta at kompassi dot fi

Description:
------------
When creating new CSR, it will add "ST=Some-State, O=Internet Widgits Pty Ltd" to the
subject if not defined in openssl_csr_new -function call. This has been a bug in PHP for a long
time.

Test script:
---------------
<?php
$config=array(
    "private_key_bits" => 2048,
    "private_key_type" => OPENSSL_KEYTYPE_RSA,
);
$privkey = openssl_pkey_new($config);

$csr = openssl_csr_new(array("C"=>"FI"), $privkey);

openssl_csr_export($csr, $csrout);
echo($csrout);

/* using same system, but command line openssl command to generate csr works just fine. I have been
using this code to do csr:
 $csr = shell_exec('openssl req -new -sha256 -key '.$tempDir.'/private.key -outform
'.$format.' -subj "'.$subject.'"');
*/
?>
$ php test.php > /tmp/foo3 
$ openssl req -in /tmp/foo3 -noout -text


Expected result:
----------------
Certificate Request:
    Data:
    Version: 0 (0x0)
    Subject: C=FI

Actual result:
--------------
Certificate Request:
    Data:
    Version: 0 (0x0)
    Subject: C=FI, ST=Some-State, O=Internet Widgits Pty Ltd



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77416&edit=1


Thread (7 messages)

« previous php.bugs (#223992) next »