Req #48520 [PATCH]: openssl_csr_new should allow multiple values/fields in dn

From: Date: Wed, 20 Dec 2023 16:24:34 +0000
Subject: Req #48520 [PATCH]: openssl_csr_new should allow multiple values/fields in dn
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-246082@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=48520&edit=1 ID: 48520 Patch added by: bukka@php.net Reported by: php at divinehawk dot com Summary: openssl_csr_new should allow multiple values/fields in dn Status: Open Type: Feature/Change Request Package: OpenSSL related Operating System: * PHP Version: 5.2.9 Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Implement request #48520: openssl_csr_new - allow multiple values in DN On GitHub: https://github.com/php/php-src/pull/12984 Patch: https://github.com/php/php-src/pull/12984.patch Previous Comments: ------------------------------------------------------------------------ [2022-01-18 19:44:17] connum at gmail dot com 13 years on, and it's still not possible to generate a CSR with multiple values for a designated name? They can be decoded using openssl_csr_get_subject() perfectly, but using that same array as dn input to create a new CSR still results in "Array to string conversion" (at least in PHP 7.4.27 I'm using right now). ------------------------------------------------------------------------ [2010-07-25 17:43:30] nirfri at hotmail dot com This patch doesn't work on multiple CNs. "commonName" => array("test2", "test") is this fixed at 5.3.2 ? ------------------------------------------------------------------------ [2009-06-10 18:38:44] php at divinehawk dot com Patch against 5.3 --- openssl.c 20 Apr 2009 09:44:29 -0000 1.98.2.5.2.41.2.29 +++ openssl.c 10 Jun 2009 18:36:57 -0000 @@ -1998,7 +1998,9 @@ CONF_VALUE * v; X509_NAME * subj; HashPosition hpos; + HashPosition subhpos; zval ** item; + zval ** subitem; subj = X509_REQ_get_subject_name(csr); /* apply values from the dn hash */ @@ -2010,6 +2012,29 @@ zend_hash_get_current_key_ex(HASH_OF(dn), &strindex, &strindexlen, &intindex, 0, &hpos); + if(Z_TYPE_PP(item) == IS_ARRAY && strindex) { + /* multi-value string */ + int nid; + nid = OBJ_txt2nid(strindex); + + if (nid != NID_undef) { + zend_hash_internal_pointer_reset_ex(HASH_OF(*item), &subhpos); + while(zend_hash_get_current_data_ex(HASH_OF(*item), (void**)&subitem, &subhpos) == SUCCESS) { + convert_to_string_ex(subitem); + if (!X509_NAME_add_entry_by_NID(subj, nid, MBSTRING_ASC, + (unsigned char*)Z_STRVAL_PP(subitem), -1, -1, 1)) { + php_error_docref(NULL TSRMLS_CC, E_WARNING, "dn: add_entry_by_NID %d -> %s (failed)", nid, Z_STRVAL_PP(subitem)); + return FAILURE; + } + zend_hash_move_forward_ex(HASH_OF(dn), &subhpos); + } + } else { + php_error_docref(NULL TSRMLS_CC, E_WARNING, "dn: %s is not a recognized name", strindex); + } + zend_hash_move_forward_ex(HASH_OF(dn), &hpos); + continue; + } + convert_to_string_ex(item); if (strindex) { ------------------------------------------------------------------------ [2009-06-10 16:29:39] pajoye@php.net Thanks for your work :) We need a patch against 5.3+ as well as test cases. PHP 5.2 won't get new features (only bug fixes). ------------------------------------------------------------------------ [2009-06-10 16:25:12] php at divinehawk dot com Patch: --- php-5.2.9/ext/openssl/openssl.c.orig 2009-06-10 06:55:27.000000000 -0400 +++ php-5.2.9/ext/openssl/openssl.c 2009-06-10 06:56:56.000000000 -0400 @@ -1707,7 +1707,9 @@ CONF_VALUE * v; X509_NAME * subj; HashPosition hpos; + HashPosition subhpos; zval ** item; + zval ** subitem; subj = X509_REQ_get_subject_name(csr); /* apply values from the dn hash */ @@ -1719,6 +1721,32 @@ zend_hash_get_current_key_ex(HASH_OF(dn), &strindex, &strindexlen, &intindex, 0, &hpos); + if(Z_TYPE_PP(item) == IS_ARRAY && strindex) + { + /* multi-value string */ + int nid; + nid = OBJ_txt2nid(strindex); + + if (nid != NID_undef) { + zend_hash_internal_pointer_reset_ex(HASH_OF(*item), &subhpos); + while(zend_hash_get_current_data_ex(HASH_OF(*item), (void**)&subitem, &subhpos) == SUCCESS) + { + convert_to_string_ex(subitem); + if (!X509_NAME_add_entry_by_NID(subj, nid, MBSTRING_ASC, + (unsigned char*)Z_STRVAL_PP(subitem), -1, -1, 1)) + { + php_error_docref(NULL TSRMLS_CC, E_WARNING, "dn: add_entry_by_NID %d -> %s (failed)", nid, Z_STRVAL_PP(subitem)); + return FAILURE; + } + zend_hash_move_forward_ex(HASH_OF(dn), &subhpos); + } + } else { + php_error_docref(NULL TSRMLS_CC, E_WARNING, "dn: %s is not a recognized name", strindex); + } + zend_hash_move_forward_ex(HASH_OF(dn), &hpos); + continue; + } + convert_to_string_ex(item); if (strindex) { ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=48520 -- Edit this bug report at https://bugs.php.net/bug.php?id=48520&edit=1

« previous php.bugs (#246082) next »