Bug #71087 [Fbk->NoF]: Phar - cannot use OpenSSL signatures with custom stub
| From: | php-bugs at lists dot php dot net | Date: | Sun, 07 Feb 2021 04:22:08 +0000 |
| Subject: | Bug #71087 [Fbk->NoF]: Phar - cannot use OpenSSL signatures with custom stub | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231971@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71087&edit=1
ID: 71087
Updated by: php-bugs@lists.php.net
Reported by: securtiy at paragonie dot com
Summary: Phar - cannot use OpenSSL signatures with custom stub
-Status: Feedback
+Status: No Feedback
Type: Bug
Package: PHAR related
Operating System: Debian 8.1 Jessie with Dotdeb
PHP Version: 5.6.16
Assigned To: cmb
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2021-01-27 11:51:09] cmb@php.net
I cannot reproduce this issue with PHP-7.4 on Windows. That
operation should be allowed anyway, so either the bug has been
fixed in the meantime, or there is some relevant difference in our
environments, or maybe my reproduce script doesn't exactly
reproduce your build script.
So, if you still have this issue with any of the actively
supported PHP versions[1], please provide a minimal self-contained
test script.
[1] <https://www.php.net/supported-versions.php>
------------------------------------------------------------------------
[2015-12-10 21:58:36] security at paragonie dot com
In our use case, this resolved the problem...
https://github.com/paragonie/php-encryption/commit/72418c9c9c4b244523da678a629227e16840de51
...but that's a workaround, not a solution.
------------------------------------------------------------------------
[2015-12-10 21:49:59] securtiy at paragonie dot com
Description:
------------
Is there any reason why we can't use Phar::setSignatureAlgorithm() after Phar::setStub()?
https://github.com/defuse/php-encryption/pull/139
If there's a reason this shouldn't allowed, could the documentation please be updated to
reflect this decision?
If this is a bug, it's breaking our ability to publish signed a .phar for defuse/php-encryption
Test script:
---------------
https://raw.githubusercontent.com/paragonie/php-encryption/29dc5e866bb08dac38fef721f3356f2e2fea76c3/other/build_phar.php
Expected result:
----------------
Silent success, but if I do this:
$phar = new \Phar(dirname(__DIR__).'/dist/defuse-crypto.phar');
$signature = $phar->getSignature();
var_dump($signature);
...it shouldn't say its "hash_type" is "SHA-1"
Actual result:
--------------
PHP Fatal error: Uncaught exception 'PharException' with message 'unable to copy
stub of old phar to new phar
"/var/www/defuse/php-encryption/dist/defuse-crypto.phar"' in
/var/www/defuse/php-encryption/other/build_phar.php:37
Stack trace:
#0 /var/www/defuse/php-encryption/other/build_phar.php(37): Phar->setSignatureAlgorithm(16,
'-----BEGIN PRIV...')
#1 {main}
thrown in /var/www/defuse/php-encryption/other/build_phar.php on line 37
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71087&edit=1