Sec Bug->Req #81703 [Opn->Csd]: stream_context_create - SSL context options

From: Date: Sun, 19 Dec 2021 22:03:14 +0000
Subject: Sec Bug->Req #81703 [Opn->Csd]: stream_context_create - SSL context options
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238497@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81703&edit=1 ID: 81703 Updated by: cmb@php.net Reported by: bugzilla77 at gmail dot com Summary: stream_context_create - SSL context options -Status: Open +Status: Closed -Type: Security +Type: Feature/Change Request Package: Streams related Operating System: All PHP Version: 8.1.1 -Assigned To: +Assigned To: cmb Block user comment: N Private report: Y New Comment: This is not a security issue, but rather a feature request. Closing as duplicate of <https://github.com/php/php-src/issues/7797>. Previous Comments: ------------------------------------------------------------------------ [2021-12-19 18:30:05] bugzilla77 at gmail dot com Description: ------------ It is dangerous to store certificates and privateKeys (without a password) on the disk. Unfortunately, this is needed to load the * .p12 file into stream_context_create. Please, add the option to set certificates and privateKeys from string content or at least from Data URLs, instead the file path only. Test script: --------------- // Using string content // -------------------- openssl_pkcs12_read(file_get_contents('cert.p12'),$certificates,'pass'); $stream_context = stream_context_create( [ 'ssl' => [ 'local_cert' => $certificates['cert'], 'local_pk' => $certificates['pkey'] ] ]); // Using Data URLs // --------------- openssl_pkcs12_read(file_get_contents('cert.p12'),$certificates,'pass'); $stream_context = stream_context_create( [ 'ssl' => [ 'local_cert' => 'data:,'.$certificates['cert'], 'local_pk' => 'data:,'.$certificates['pkey'] ] ]); // Hack: temp files // ---------------- openssl_pkcs12_read(file_get_contents('cert.p12'),$certificates,'pass'); file_put_contents('cert.temp',$certificates['cert']); file_put_contents('pkey.temp',$certificates['pkey']); $stream_context = stream_context_create( [ 'ssl' => [ 'local_cert' => 'cert.temp', 'local_pk' => 'pkey.temp' ] ]); Expected result: ---------------- Reading certificates and privateKeys without temp files. Actual result: -------------- Reading certificates and privateKeys only with temp files. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81703&edit=1

« previous php.bugs (#238497) next »