Req #68366 [Asn]: Does not use certificate's signing algorithm

From: Date: Thu, 16 Dec 2021 21:28:04 +0000
Subject: Req #68366 [Asn]: Does not use certificate's signing algorithm
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238455@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68366&edit=1 ID: 68366 Updated by: bukka@php.net Reported by: jean-luc dot cooke at trustificorp dot com Summary: Does not use certificate's signing algorithm Status: Assigned Type: Feature/Change Request Package: OpenSSL related Operating System: All PHP Version: 5.4.34 Assigned To: bukka Block user comment: N Private report: Y New Comment: What I mean is basically to add a parameter that would make use of PKCS7_add_signature Previous Comments: ------------------------------------------------------------------------ [2021-12-16 21:27:03] bukka@php.net This is not a bug as it is just using the same default as OpenSSL ( see notes in https://www.openssl.org/docs/man1.1.1/man3/PKCS7_sign.html ). We could however add a way to overwrite it. ------------------------------------------------------------------------ [2014-11-06 16:24:38] jean-luc dot cooke at trustificorp dot com Description: ------------ --- From manual page: http://www.php.net/function.openssl-pkcs7-sign --- Most certs are being issued with sha256WithRSAEncryption but the php openssl_pkcs7_sign() function always uses sha1WithRSAEncryption. At a minimum there should be a way to specify the signing algorithm with an optional parameter like openssl_sign() does. Test script: --------------- $ret = openssl_pkcs7_sign( $fileTmp, $fileSigned, $signInfo['cert'], array($signInfo['key'], $signInfo['keypass']), $signHeaders, PKCS7_DETACHED, $signInfo['extracerts'] ); Expected result: ---------------- After extracting smime.p7s from "$fileSigned" in the Test Script, check to see how it was signed using the command-line: openssl asn1parse -inform pem -in smime.p7s -dump -i | less -S Look for ":messageDigest". You'll see it's 20 bytes long (160bits which is SHA-1). Plus you'll see a few lines above ":messageDigest" mention of ":sha1". Actual result: -------------- After extracting smime.p7s from "$fileSigned" in the Test Script, check to see how it was signed using the command-line: openssl asn1parse -inform pem -in smime.p7s -dump -i | less -S Look for ":messageDigest". You SHOULD see it's 32 bytes long (160bits which is SHA-256). Plus you SHOULD see a few lines above ":messageDigest" mention of ":sha256". ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68366&edit=1

« previous php.bugs (#238455) next »