Bug #66122 [Opn->Csd]: Certification cannot be used directly after openssl_csr_sign

From: Date: Thu, 23 Nov 2023 13:02:53 +0000
Subject: Bug #66122 [Opn->Csd]: Certification cannot be used directly after openssl_csr_sign
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-245879@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66122&edit=1 ID: 66122 Updated by: bukka@php.net Reported by: phpbugs at lavoie dot sl Summary: Certification cannot be used directly after openssl_csr_sign -Status: Open +Status: Closed Type: Bug Package: OpenSSL related Operating System: Linux/Mac PHP Version: 5.5.6 -Assigned To: +Assigned To: bukka Block user comment: N Private report: N New Comment: Apology for very late response. I have done a bit of testing and checking and this actually seems like an old issue in OpenSSL 1.0.2 and below. I was able to recreate only with 1.0.2 but didn't test older versions as we don't support them anymore. OpenSSL probably incorrectly set issuer or serial on cert because pkcs7 decrypt cannot find matching cert. I don't want to spend too much time digging to exactly identify what OpenSSL issue it was as it is fixed in 1.1.1+ (including 3.0+ ofc). So there's not much point to spend too much time on this. I just quickly checked if there's some potential fix in the extension code for 1.0.2 but don't think this can be easily done. So will just close this as OpenSSL issue that got fixed. Previous Comments: ------------------------------------------------------------------------ [2013-11-20 04:40:31] phpbugs at lavoie dot sl Description: ------------ When generating a CRT using KEY/CSR, the certificate resource is not "ready". To use it, you have to export and import it back. The test was done using a CA or a selfsigned. Tested on 3 systems: OSX 10.9 PHP 5.5.6 (brew) OpenSSL 1.0.1e Ubuntu PHP 5.4.21-1+debphp.org~quantal+1 OpenSSL 1.0.1c PHP 5.3.10-1ubuntu3.6 OpenSSL 1.0.1 (Native) If nobody can reproduce this, I can post the rest of the system configurations Test script: --------------- <?php $key = openssl_pkey_new(); $csr = openssl_csr_new(array(), $key); $crt = openssl_csr_sign($csr, null, $key, 365 * 100); openssl_pkcs7_encrypt($plain1, $enc, $crt, array('foo' => 'bar')); openssl_pkcs7_decrypt($enc, $plain2, $crt, $key); // error, empty ?> Full example: https://gist.github.com/lavoiesl/7557763/raw/openssl-test.php Expected result: ---------------- string(0) "hello" string(5) "hello" string(0) "hello" array(0) { } Actual result: -------------- error:21070073:PKCS7 routines:PKCS7_dataDecode:no recipient matches certificatestring(0) "" string(5) "hello" error:21070073:PKCS7 routines:PKCS7_dataDecode:no recipient matches certificatestring(0) "" array(0) { } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66122&edit=1

« previous php.bugs (#245879) next »