Bug #71087 [Opn->Fbk]: Phar - cannot use OpenSSL signatures with custom stub
| From: | cmb@php.net | Date: | Wed, 27 Jan 2021 11:51:09 +0000 |
| Subject: | Bug #71087 [Opn->Fbk]: Phar - cannot use OpenSSL signatures with custom stub | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231793@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71087&edit=1
ID: 71087
Updated by: cmb@php.net
Reported by: securtiy at paragonie dot com
Summary: Phar - cannot use OpenSSL signatures with custom
stub
-Status: Open
+Status: Feedback
Type: Bug
Package: PHAR related
Operating System: Debian 8.1 Jessie with Dotdeb
PHP Version: 5.6.16
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
I cannot reproduce this issue with PHP-7.4 on Windows. That
operation should be allowed anyway, so either the bug has been
fixed in the meantime, or there is some relevant difference in our
environments, or maybe my reproduce script doesn't exactly
reproduce your build script.
So, if you still have this issue with any of the actively
supported PHP versions[1], please provide a minimal self-contained
test script.
[1] <https://www.php.net/supported-versions.php>
Previous Comments:
------------------------------------------------------------------------
[2015-12-10 21:58:36] security at paragonie dot com
In our use case, this resolved the problem...
https://github.com/paragonie/php-encryption/commit/72418c9c9c4b244523da678a629227e16840de51
...but that's a workaround, not a solution.
------------------------------------------------------------------------
[2015-12-10 21:49:59] securtiy at paragonie dot com
Description:
------------
Is there any reason why we can't use Phar::setSignatureAlgorithm() after Phar::setStub()?
https://github.com/defuse/php-encryption/pull/139
If there's a reason this shouldn't allowed, could the documentation please be updated to
reflect this decision?
If this is a bug, it's breaking our ability to publish signed a .phar for defuse/php-encryption
Test script:
---------------
https://raw.githubusercontent.com/paragonie/php-encryption/29dc5e866bb08dac38fef721f3356f2e2fea76c3/other/build_phar.php
Expected result:
----------------
Silent success, but if I do this:
$phar = new \Phar(dirname(__DIR__).'/dist/defuse-crypto.phar');
$signature = $phar->getSignature();
var_dump($signature);
...it shouldn't say its "hash_type" is "SHA-1"
Actual result:
--------------
PHP Fatal error: Uncaught exception 'PharException' with message 'unable to copy
stub of old phar to new phar
"/var/www/defuse/php-encryption/dist/defuse-crypto.phar"' in
/var/www/defuse/php-encryption/other/build_phar.php:37
Stack trace:
#0 /var/www/defuse/php-encryption/other/build_phar.php(37): Phar->setSignatureAlgorithm(16,
'-----BEGIN PRIV...')
#1 {main}
thrown in /var/www/defuse/php-encryption/other/build_phar.php on line 37
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71087&edit=1