[php-src] Issue #13343: openssl_x509_parse should not allow omitted seconds in UTCTimes
| From: | botovq | Date: | Tue, 06 Feb 2024 20:43:33 +0000 |
| Subject: | [php-src] Issue #13343: openssl_x509_parse should not allow omitted seconds in UTCTimes | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-246423@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/13343
Author: botovq
### Description
PR #2444, "openssl_x509_parse fails to parse ASN.1 UTCTime without seconds" added support
for UTCTimes in certificates omitting seconds. This seems incorrect. While it is true that seconds
are optional in the ASN.1 specification of UTCTime in [ITU T-REC X.680][0] section 47.3, the same is
not true for its DER encoding, in particular for certificates or CRLs. [RFC 5280, 4.1.2.5.1][1]:
```
For the purposes of this profile, UTCTime values MUST be expressed in
Greenwich Mean Time (Zulu) and MUST include seconds (i.e., times are
YYMMDDHHMMSSZ), even where the number of seconds is zero.
```
[ITU-TREC X.690][2], section 11.8.2 also states explicitly: "the seconds shall always be
present".
Similar statements hold true for
GeneralizedTime. (For some reason no exception was
made despite the fact that the ASN.1 spec allows omitting minutes or seconds).
As an aside, it is a bit dangerous to use strlen() on the data in an
ASN1_STRING. These have historically been NUL terminated in OpenSSL, but
this is an implementation detail, not a documented API contract. There is no real reason for them to
be NUL-terminated: ASN.1 strings are length-prefixed strings.
[0]: https://www.itu.int/rec/T-REC-X.680-202102-I/en
[1]: https://www.rfc-editor.org/rfc/rfc5280#section-4.1.2.5.1
[2]: https://www.itu.int/rec/T-REC-X.690-202102-I/ens
### PHP Version
PHP 8.3.2
### Operating System
_No response_