Bug #52093 [Csd]: openssl_csr_sign truncates $serial

From: Date: Tue, 03 Aug 2021 14:14:08 +0000
Subject: Bug #52093 [Csd]: openssl_csr_sign truncates $serial
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235568@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52093&edit=1 ID: 52093 Updated by: cmb@php.net Reported by: dreuzel at belgacom dot net Summary: openssl_csr_sign truncates $serial Status: Closed Type: Bug Package: OpenSSL related Operating System: win7 PHP Version: 5.3.2 Assigned To: cmb Block user comment: N Private report: N New Comment: @izorkin, I can't explain that build failure. The function is supposed to be available with OpenSSL >= 1.1.0. Anyhow, please open a new ticket, because the fix for this ticket has already been released, so re-opening this ticket would be confusing at best. Previous Comments: ------------------------------------------------------------------------ [2021-08-03 13:47:42] izorkin at elven dot pw After this patch error build php 7.4 and php 8.0: ``` /build/php-src-7.4.22/ext/openssl/openssl.c: In function 'zif_openssl_csr_sign': /build/php-src-7.4.22/ext/openssl/openssl.c:3528:2: warning: implicit declaration of function 'ASN1_INTEGER_set_int64'; did you mean 'ASN1_INTEGER_set'? [^[]8;;https://gcc.gnu.org/onlinedocs/gcc/Warning-Options.html#index-Wimplicit-function-declaration^G-Wimplicit-function-declaration^[]8;;^G] 3528 | ASN1_INTEGER_set_int64(X509_get_serialNumber(new_cert), serial); | ^~~~~~~~~~~~~~~~~~~~~~ | ASN1_INTEGER_set ``` Use Openssl version 1.1.1k. ------------------------------------------------------------------------ [2021-07-01 13:46:42] git@php.net Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/334387bb7097840789fbc95bd38c425645705d30 Log: Fix #52093: openssl_csr_sign truncates $serial ------------------------------------------------------------------------ [2021-06-30 12:37:31] cmb@php.net The following pull request has been associated: Patch Name: Fix #52093: openssl_csr_sign silently truncates $serial On GitHub: https://github.com/php/php-src/pull/7209 Patch: https://github.com/php/php-src/pull/7209.patch ------------------------------------------------------------------------ [2019-08-18 20:35:40] hunterr83 at hotmail dot com Not sure if the same thing, but very related. When I do print(PHP_INT_MAX), I get a value of 9223372036854775807. However, when I try to pass in that value to the serial number parameter, the certificate that is generated shows a serial value of ff, which is 255. Similarly, if I go down one count in value and pass in 9223372036854775806, then I get a final serial number of fe, which is 254. If I pass in 4294967290, then I get fa, which is 250. Some rough testing shows that the maximum value the function is willing to accept is something a bit higher than 4,000,000,000. Once you go above whatever the actual cap is, you start to see some really strange serial numbers. I feel if it's too difficult to support the PHP_INT_MAX value, then we could at least throw an error if the integer being passed in is more than the function can support. ------------------------------------------------------------------------ [2017-08-02 14:27:12] narf at devilix dot net There's a worse problem with this ... It's not even supposed to be a decimal number. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=52093 -- Edit this bug report at https://bugs.php.net/bug.php?id=52093&edit=1

« previous php.bugs (#235568) next »