#25614 [Com]: openssl_pkey_get_public() fails when given a private key
| From: | andrey dot gladilin at gmail dot com | Date: | Thu, 01 Jun 2006 14:22:34 +0000 |
| Subject: | #25614 [Com]: openssl_pkey_get_public() fails when given a private key | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-97930@lists.php.net to get a copy of this message | ||
ID: 25614
Comment by: andrey dot gladilin at gmail dot com
Reported By: six at t0x dot net
Status: Suspended
Bug Type: OpenSSL related
Operating System: Linux 2.4
PHP Version: 6CVS, 5CVS, 4CVS
Assigned To: wez
New Comment:
To fix this bug you have to change file
php-4.4.0/ext/openssl/openssl.c. php-4.4.0 is just my source
distributive of PHP.
In file openssl.c replace string
key = PEM_read_bio_PUBKEY(in, NULL,NULL, NULL);
with another code
RSA * rsa = PEM_read_bio_RSAPublicKey(in, NULL, NULL, NULL);
BIO_free(in);
if(NULL == rsa) {
throw Exc("Error while processing the Public Key.");
}
pkey = EVP_PKEY_new();
EVP_PKEY_assign_RSA(pkey, rsa);
Unsusccessfully I have no time to test it, but this must work. Hope to
see this bugfix in a new release.
Previous Comments:
------------------------------------------------------------------------
[2003-09-23 12:10:32] wez@php.net
The documentation for openssl_pkey_new() is incorrect.
It doesn't generate a pair of keys at all.
openssl_pkey_get_public() was also slightly broken, in
that it didn't detect that it couldn't get the public key
from the private key. You can use it to get the public key out of an
x509 certificate though (yeah, it sounds weird).
I've added a "fix" for this problem to the CVS that will now warn you
about not being able to get the public key from a private key. This
fix will be in 4.3.4.
This stuff is a little bit messy, and its been a while since anyone did
any real work on the openssl extension.
The openssl stuff could probably benefit from a review, but this won't
happen for PHP 4.3.x, so I'm going to suspend this report until PHP 5
or PHP 5.1 when I get more time.
------------------------------------------------------------------------
[2003-09-20 12:27:26] six at t0x dot net
Description:
------------
PHP manual states that : "openssl_pkey_new() generates a new private
and public key pair. The public component of the key can be obtained
using openssl_pkey_get_public()."
However, the following script (see "reproduce-code" section) seems to
indicate that openssl_pkey_get_public is broken in some way ...
it should be noted that the two exports ($ex_k and $ex_p) start (and
end) with a "RSA PRIVATE KEY" header line
Reproduce code:
---------------
<?
$k = openssl_pkey_new();
$p = openssl_pkey_get_public($k);
echo "php version ".phpversion()."\n\n";
echo "generated private key resource : $k\n";
echo "generated public key resource : $p\n\n";
openssl_pkey_export($k, $ex_k);
openssl_pkey_export($p, $ex_p);
if ($ex_k == $ex_p) echo "exports match :(\n";
?>
Expected result:
----------------
php version 4.3.3
generated private key resource : Resource id #4
generated public key resource : Resource id #5
Actual result:
--------------
php version 4.3.3
generated private key resource : Resource id #4
generated public key resource : Resource id #4
exports match :(
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=25614&edit=1