Bug #51647 [Opn->Csd]: Certificate file without private key (pk in another file) doesn't work

From: Date: Thu, 09 Apr 2020 09:47:58 +0000
Subject: Bug #51647 [Opn->Csd]: Certificate file without private key (pk in another file) doesn't work
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226505@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=51647&edit=1 ID: 51647 Updated by: cmb@php.net Reported by: andrey@php.net Summary: Certificate file without private key (pk in another file) doesn't work -Status: Open +Status: Closed Type: Bug Package: OpenSSL related Operating System: Linux PHP Version: 5.3SVN-2010-04-23 (SVN) -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Closing, since this is fixed as of PHP 5.3.3 (IOW, the commit never had been reverted). Previous Comments: ------------------------------------------------------------------------ [2015-07-10 13:21:24] spam2 at rhsoft dot net Related To: Bug #70039 ------------------------------------------------------------------------ [2015-07-10 11:33:13] spam2 at rhsoft dot net Related To: Bug #70039 ------------------------------------------------------------------------ [2014-03-04 18:55:10] rdlowrey@php.net > The user is forced to put keys in the same file, > which is not always possible. I'm drawing a blank on when this would not be possible. The only thing that needs to happen in order for this to work is the concatenation of the private key and the public cert into the same file. Are there scenarios where this isn't possible that I'm missing? Otherwise I wouldn't really consider this a bug. ------------------------------------------------------------------------ [2014-01-30 17:46:28] daverandom@php.net Pierre/Andrey Are we happy that this bug is fixed? The context option that was added by the patch is not currently documented. I will be helping to update the documentation for the recent OpenSSL changes, can I include this in the docs as well? Thanks, Chris ------------------------------------------------------------------------ [2010-04-23 17:28:54] andrey@php.net Here is the new patch, already committed, also to be found in the commit email. Index: ext/openssl/openssl.c =================================================================== --- ext/openssl/openssl.c (revision 298371) +++ ext/openssl/openssl.c (working copy) @@ -4445,6 +4445,7 @@ EVP_PKEY *key = NULL; SSL *tmpssl; char resolved_path_buff[MAXPATHLEN]; + const char * private_key = NULL; if (VCWD_REALPATH(certfile, resolved_path_buff)) { /* a certificate to use for authentication */ @@ -4452,10 +4453,21 @@ php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set local cert chain file `%s'; Check that your cafile/capath settings include details of your certificate and its issuer", certfile); return NULL; } + GET_VER_OPT_STRING("local_pk", private_key); - if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff, SSL_FILETYPE_PEM) != 1) { - php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file `%s'", resolved_path_buff); - return NULL; + if (private_key) { + char resolved_path_buff_pk[MAXPATHLEN]; + if (VCWD_REALPATH(private_key, resolved_path_buff_pk)) { + if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff_pk, SSL_FILETYPE_PEM) != 1) { + php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file `%s'", resolved_path_buff_pk); + return NULL; + } + } + } else { + if (SSL_CTX_use_PrivateKey_file(ctx, resolved_path_buff, SSL_FILETYPE_PEM) != 1) { + php_error_docref(NULL TSRMLS_CC, E_WARNING, "Unable to set private key file `%s'", resolved_path_buff); + return NULL; + } } tmpssl = SSL_new(ctx); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=51647 -- Edit this bug report at https://bugs.php.net/bug.php?id=51647&edit=1

« previous php.bugs (#226505) next »