Bug #76676 [Csd]: OPENSSL_KEYTYPE_EC (and others) not supported by openssl_public_encrypt()

From: Date: Fri, 25 Nov 2022 15:08:02 +0000
Subject: Bug #76676 [Csd]: OPENSSL_KEYTYPE_EC (and others) not supported by openssl_public_encrypt()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242916@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76676&edit=1 ID: 76676 Updated by: bukka@php.net Reported by: kaplan@php.net Summary: OPENSSL_KEYTYPE_EC (and others) not supported by openssl_public_encrypt() Status: Closed Type: Bug Package: OpenSSL related PHP Version: 7.1.20 Assigned To: bukka Block user comment: N Private report: N New Comment: Just to add, the supported key types are only those that supports encryption. This is all checked by OpenSSL so errors can be seen by calling openssl_error_string(). Previous Comments: ------------------------------------------------------------------------ [2022-11-25 15:00:09] bukka@php.net So OPENSSL_KEYTYPE_EC is now supported for openssl_pkey_new so that part works for me fine with PHP 8.1. However encrypt doesn't work here but the reason that secp384r1 cannot be used for encryption but only for signing. It means nothing to do here so closing. ------------------------------------------------------------------------ [2018-07-28 13:47:55] kaplan@php.net Description: ------------ Comparing key types supported by php_openssl_is_private_key() to the ones supported by openssl_public_key() shows many are missing. php_openssl_is_private_key recognizes: EVP_PKEY_RSA / EVP_PKEY_RSA2 EVP_PKEY_DSA / EVP_PKEY_DSA1 / EVP_PKEY_DSA2 / EVP_PKEY_DSA3 / EVP_PKEY_DSA4 EVP_PKEY_DH EVP_PKEY_EC openssl_private_encrypt supports EVP_PKEY_RSA / EVP_PKEY_RSA2 openssl_private_decrypt supports EVP_PKEY_RSA / EVP_PKEY_RSA2 openssl_public_decrypt supports EVP_PKEY_RSA / EVP_PKEY_RSA2 Maybe also use EVP_PKEY_base_id() as in openssl_pkey_get_details() which does support all the keys as php_openssl_is_private_key(). Tested in 7.1.14, 7.2.6 and master (July 26th, 2018). Test script: --------------- <?php $pair = generateKeyPair(true); $public = $pair['public']; $ciphertext = "111-11-1111"; $res = openssl_public_encrypt($ciphertext, $enc, $public, OPENSSL_PKCS1_OAEP_PADDING); if($res){ var_dump(bin2hex($enc)); } else { echo "Failed to encrypt :("; } function generateKeyPair(bool $ec){ $params = $ec ? [ 'private_key_bits' => 384, 'private_key_type' => OPENSSL_KEYTYPE_EC, 'curve_name' => 'secp384r1' ] : [ 'private_key_bits' => 3072, 'private_key_type' => OPENSSL_KEYTYPE_RSA ]; $res = openssl_pkey_new($params); openssl_pkey_export($res, $privKey); $pubKey = openssl_pkey_get_details($res); $pubKey = $pubKey["key"]; openssl_free_key($res); return ['private'=>$privKey, 'public'=>$pubKey]; } ?> Expected result: ---------------- 1. for OPENSSL_KEYTYPE_EC to be suppprted. 2. for missing keytype be part of the error message. Actual result: -------------- Warning: openssl_public_encrypt(): key type not supported in this PHP build! ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76676&edit=1

« previous php.bugs (#242916) next »