Bug #77416 [Opn->Wfx]: openssl_csr_new add fields to subject

From: Date: Sun, 01 Dec 2019 19:39:33 +0000
Subject: Bug #77416 [Opn->Wfx]: openssl_csr_new add fields to subject
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223993@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77416&edit=1

 ID:                 77416
 Updated by:         bukka@php.net
 Reported by:        joose dot vettenranta at kompassi dot fi
 Summary:            openssl_csr_new  add fields to subject
-Status:             Open
+Status:             Wont fix
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Linux
 PHP Version:        7.2.13
-Assigned To:        
+Assigned To:        bukka
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2019-12-01 19:39:05] bukka@php.net

PHP is using default openssl config which is usually the system one but depends on the installation.
This can be overwritten using OPENSSL_CONF environment variable. The default config is always loaded
which is on purpose and it can't be changed due to BC.

So the only solution in here is to either change your default config or use specific config for
openssl_csr_new.

------------------------------------------------------------------------
[2019-01-06 21:30:56] joose dot vettenranta at kompassi dot fi

If I create own openssl.cnf file containing: 
distinguished_name  = req_distinguished_name
[req_distinguished_name]
[v3_req]
[v3_ca]

it will work as expected

------------------------------------------------------------------------
[2019-01-06 21:12:44] joose dot vettenranta at kompassi dot fi

I need different kind of subjects when I am creating certificates for systems other than SSL. That
is why to subject is completely different what is normally (SSL) used.

------------------------------------------------------------------------
[2019-01-06 21:09:37] joose dot vettenranta at kompassi dot fi

I have not checked. But I have tried this with different distros, different php -versions and with
different operating systems (macos and linux). Also have tried docker images. And as I notided in
the test script, doing the same thing on the same computer using command line openssl command, it
will work as expected.

------------------------------------------------------------------------
[2019-01-06 19:27:25] requinix@php.net

How does your openssl.cnf look?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77416


--
Edit this bug report at https://bugs.php.net/bug.php?id=77416&edit=1


Thread (7 messages)

« previous php.bugs (#223993) next »