Bug #71087 [Fbk->NoF]: Phar - cannot use OpenSSL signatures with custom stub

From: Date: Sun, 07 Feb 2021 04:22:08 +0000
Subject: Bug #71087 [Fbk->NoF]: Phar - cannot use OpenSSL signatures with custom stub
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231971@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71087&edit=1 ID: 71087 Updated by: php-bugs@lists.php.net Reported by: securtiy at paragonie dot com Summary: Phar - cannot use OpenSSL signatures with custom stub -Status: Feedback +Status: No Feedback Type: Bug Package: PHAR related Operating System: Debian 8.1 Jessie with Dotdeb PHP Version: 5.6.16 Assigned To: cmb Private report: N New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. Previous Comments: ------------------------------------------------------------------------ [2021-01-27 11:51:09] cmb@php.net I cannot reproduce this issue with PHP-7.4 on Windows. That operation should be allowed anyway, so either the bug has been fixed in the meantime, or there is some relevant difference in our environments, or maybe my reproduce script doesn't exactly reproduce your build script. So, if you still have this issue with any of the actively supported PHP versions[1], please provide a minimal self-contained test script. [1] <https://www.php.net/supported-versions.php> ------------------------------------------------------------------------ [2015-12-10 21:58:36] security at paragonie dot com In our use case, this resolved the problem... https://github.com/paragonie/php-encryption/commit/72418c9c9c4b244523da678a629227e16840de51 ...but that's a workaround, not a solution. ------------------------------------------------------------------------ [2015-12-10 21:49:59] securtiy at paragonie dot com Description: ------------ Is there any reason why we can't use Phar::setSignatureAlgorithm() after Phar::setStub()? https://github.com/defuse/php-encryption/pull/139 If there's a reason this shouldn't allowed, could the documentation please be updated to reflect this decision? If this is a bug, it's breaking our ability to publish signed a .phar for defuse/php-encryption Test script: --------------- https://raw.githubusercontent.com/paragonie/php-encryption/29dc5e866bb08dac38fef721f3356f2e2fea76c3/other/build_phar.php Expected result: ---------------- Silent success, but if I do this: $phar = new \Phar(dirname(__DIR__).'/dist/defuse-crypto.phar'); $signature = $phar->getSignature(); var_dump($signature); ...it shouldn't say its "hash_type" is "SHA-1" Actual result: -------------- PHP Fatal error: Uncaught exception 'PharException' with message 'unable to copy stub of old phar to new phar "/var/www/defuse/php-encryption/dist/defuse-crypto.phar"' in /var/www/defuse/php-encryption/other/build_phar.php:37 Stack trace: #0 /var/www/defuse/php-encryption/other/build_phar.php(37): Phar->setSignatureAlgorithm(16, '-----BEGIN PRIV...') #1 {main} thrown in /var/www/defuse/php-encryption/other/build_phar.php on line 37 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71087&edit=1

« previous php.bugs (#231971) next »