Sec Bug->Req #81703 [Opn->Csd]: stream_context_create - SSL context options
| From: | cmb@php.net | Date: | Sun, 19 Dec 2021 22:03:14 +0000 |
| Subject: | Sec Bug->Req #81703 [Opn->Csd]: stream_context_create - SSL context options | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238497@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81703&edit=1
ID: 81703
Updated by: cmb@php.net
Reported by: bugzilla77 at gmail dot com
Summary: stream_context_create - SSL context options
-Status: Open
+Status: Closed
-Type: Security
+Type: Feature/Change Request
Package: Streams related
Operating System: All
PHP Version: 8.1.1
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
This is not a security issue, but rather a feature request.
Closing as duplicate of <https://github.com/php/php-src/issues/7797>.
Previous Comments:
------------------------------------------------------------------------
[2021-12-19 18:30:05] bugzilla77 at gmail dot com
Description:
------------
It is dangerous to store certificates and privateKeys (without a password) on the disk.
Unfortunately, this is needed to load the * .p12 file into stream_context_create.
Please, add the option to set certificates and privateKeys from string content or at least from Data
URLs, instead the file path only.
Test script:
---------------
// Using string content
// --------------------
openssl_pkcs12_read(file_get_contents('cert.p12'),$certificates,'pass');
$stream_context = stream_context_create(
[ 'ssl' => [ 'local_cert' => $certificates['cert'],
'local_pk' => $certificates['pkey']
]
]);
// Using Data URLs
// ---------------
openssl_pkcs12_read(file_get_contents('cert.p12'),$certificates,'pass');
$stream_context = stream_context_create(
[ 'ssl' => [ 'local_cert' =>
'data:,'.$certificates['cert'],
'local_pk' => 'data:,'.$certificates['pkey']
]
]);
// Hack: temp files
// ----------------
openssl_pkcs12_read(file_get_contents('cert.p12'),$certificates,'pass');
file_put_contents('cert.temp',$certificates['cert']);
file_put_contents('pkey.temp',$certificates['pkey']);
$stream_context = stream_context_create(
[ 'ssl' => [ 'local_cert' => 'cert.temp',
'local_pk' => 'pkey.temp'
]
]);
Expected result:
----------------
Reading certificates and privateKeys without temp files.
Actual result:
--------------
Reading certificates and privateKeys only with temp files.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81703&edit=1