Sec Bug->Req #68366 [Asn]: Does not use certificate's signing algorithm

From: Date: Thu, 16 Dec 2021 21:27:03 +0000
Subject: Sec Bug->Req #68366 [Asn]: Does not use certificate's signing algorithm
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238454@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68366&edit=1

 ID:                 68366
 Updated by:         bukka@php.net
 Reported by:        jean-luc dot cooke at trustificorp dot com
 Summary:            Does not use certificate's signing algorithm
 Status:             Assigned
-Type:               Security
+Type:               Feature/Change Request
 Package:            OpenSSL related
 Operating System:   All
 PHP Version:        5.4.34
 Assigned To:        bukka
 Block user comment: N
 Private report:     Y

 New Comment:

This is not a bug as it is just using the same default as OpenSSL ( see notes in https://www.openssl.org/docs/man1.1.1/man3/PKCS7_sign.html
). We could however add a way to overwrite it.


Previous Comments:
------------------------------------------------------------------------
[2014-11-06 16:24:38] jean-luc dot cooke at trustificorp dot com

Description:
------------
---
From manual page: http://www.php.net/function.openssl-pkcs7-sign
---

Most certs are being issued with sha256WithRSAEncryption but the php openssl_pkcs7_sign() function
always uses sha1WithRSAEncryption.  At a minimum there should be a way to specify the signing
algorithm with an optional parameter like openssl_sign() does.

Test script:
---------------
                $ret = openssl_pkcs7_sign(
                        $fileTmp,
                        $fileSigned,
                        $signInfo['cert'],
                        array($signInfo['key'], $signInfo['keypass']),
                        $signHeaders,
                        PKCS7_DETACHED,
                        $signInfo['extracerts']
                );

Expected result:
----------------
After extracting smime.p7s from "$fileSigned" in the Test Script, check to see how it was
signed using the command-line:

 openssl asn1parse -inform pem -in smime.p7s -dump -i | less -S

Look for ":messageDigest".  You'll see it's 20 bytes long (160bits which is
SHA-1).  Plus you'll see a few lines above ":messageDigest" mention of
":sha1".

Actual result:
--------------
After extracting smime.p7s from "$fileSigned" in the Test Script, check to see how it was
signed using the command-line:

 openssl asn1parse -inform pem -in smime.p7s -dump -i | less -S

Look for ":messageDigest".  You SHOULD see it's 32 bytes long (160bits which is
SHA-256).  Plus you SHOULD see a few lines above ":messageDigest" mention of
":sha256".


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68366&edit=1


Thread (1 message)

  • bukka@php.net
  • Unknown Message
    • bukka@php.net
« previous php.bugs (#238454) next »