Req #48520 [Opn->Csd]: openssl_csr_new should allow multiple values/fields in dn

From: Date: Thu, 21 Dec 2023 19:14:23 +0000
Subject: Req #48520 [Opn->Csd]: openssl_csr_new should allow multiple values/fields in dn
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-246098@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=48520&edit=1

 ID:                 48520
 Updated by:         bukka@php.net
 Reported by:        php at divinehawk dot com
 Summary:            openssl_csr_new should allow multiple values/fields
                     in dn
-Status:             Open
+Status:             Closed
 Type:               Feature/Change Request
 Package:            OpenSSL related
 Operating System:   *
 PHP Version:        5.2.9
-Assigned To:        
+Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

PR merged: https://github.com/php/php-src/commit/48ebe588cd18867ead009576c0cdbaa29e953398


Previous Comments:
------------------------------------------------------------------------
[2023-12-20 16:24:34] bukka@php.net

The following pull request has been associated:

Patch Name: Implement request #48520: openssl_csr_new - allow multiple values in DN
On GitHub:  https://github.com/php/php-src/pull/12984
Patch:      https://github.com/php/php-src/pull/12984.patch

------------------------------------------------------------------------
[2022-01-18 19:44:17] connum at gmail dot com

13 years on, and it's still not possible to generate a CSR with multiple values for a
designated name?

They can be decoded using openssl_csr_get_subject() perfectly, but using that same array as dn input
to create a new CSR still results in "Array to string conversion" (at least in PHP 7.4.27
I'm using right now).

------------------------------------------------------------------------
[2010-07-25 17:43:30] nirfri at hotmail dot com

This patch doesn't work on multiple CNs.

"commonName" => array("test2", "test")

is this fixed at 5.3.2 ?

------------------------------------------------------------------------
[2009-06-10 18:38:44] php at divinehawk dot com

Patch against 5.3

--- openssl.c	20 Apr 2009 09:44:29 -0000	1.98.2.5.2.41.2.29
+++ openssl.c	10 Jun 2009 18:36:57 -0000
@@ -1998,7 +1998,9 @@
 		CONF_VALUE * v;
 		X509_NAME * subj;
 		HashPosition hpos;
+		HashPosition subhpos;
 		zval ** item;
+		zval ** subitem;
 		
 		subj = X509_REQ_get_subject_name(csr);
 		/* apply values from the dn hash */
@@ -2010,6 +2012,29 @@
 			
 			zend_hash_get_current_key_ex(HASH_OF(dn), &strindex, &strindexlen, &intindex, 0,
&hpos);
 
+			if(Z_TYPE_PP(item) == IS_ARRAY && strindex) {
+				/* multi-value string */
+				int nid;
+				nid = OBJ_txt2nid(strindex);
+					
+				if (nid != NID_undef) {
+					zend_hash_internal_pointer_reset_ex(HASH_OF(*item), &subhpos);
+					while(zend_hash_get_current_data_ex(HASH_OF(*item), (void**)&subitem, &subhpos) ==
SUCCESS) {	 
+						convert_to_string_ex(subitem);
+						if (!X509_NAME_add_entry_by_NID(subj, nid, MBSTRING_ASC, 
+								(unsigned char*)Z_STRVAL_PP(subitem), -1, -1, 1)) {
+							php_error_docref(NULL TSRMLS_CC, E_WARNING, "dn: add_entry_by_NID %d -> %s
(failed)", nid, Z_STRVAL_PP(subitem));
+							return FAILURE;
+						}
+						zend_hash_move_forward_ex(HASH_OF(dn), &subhpos);
+					}
+				} else {
+					php_error_docref(NULL TSRMLS_CC, E_WARNING, "dn: %s is not a recognized name",
strindex);
+				}
+				zend_hash_move_forward_ex(HASH_OF(dn), &hpos);
+				continue;
+			}
+
 			convert_to_string_ex(item);
 
 			if (strindex) {

------------------------------------------------------------------------
[2009-06-10 16:29:39] pajoye@php.net


Thanks for your work :)

We need a patch against 5.3+ as well as test cases.

PHP 5.2 won't get new features (only bug fixes).



------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=48520


--
Edit this bug report at https://bugs.php.net/bug.php?id=48520&edit=1


Thread (10 messages)

« previous php.bugs (#246098) next »