#37820 [Opn->Asn]: Missing algorithm type in openssl_verify().
| From: | tony2001@php.net | Date: | Mon, 19 Jun 2006 16:59:36 +0000 |
| Subject: | #37820 [Opn->Asn]: Missing algorithm type in openssl_verify(). | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-98507@lists.php.net to get a copy of this message | ||
ID: 37820
Updated by: tony2001@php.net
Reported By: php at lehis dot ru
-Status: Open
+Status: Assigned
Bug Type: OpenSSL related
Operating System: FreeBSD 6.1
PHP Version: 5.1.4
-Assigned To:
+Assigned To: wez
Previous Comments:
------------------------------------------------------------------------
[2006-06-15 18:30:36] php at lehis dot ru
Description:
------------
Can't change algorythm type in openssl_verify(). So, if data signs by
MD5, openssl_verify() always returns FALSE.
It is caused by openssl_verify() always using the SHA1 algorythm, so I
think it can be improved by adding the 4th parameter (algorythm to use)
to this function, for example, like this: openssl_verify($data,
$signature, $pubkeyid, [, int signature_alg]);
Reproduce code:
---------------
openssl_sign($data, $signature, $priv_key_id, OPENSSL_ALGO_MD5);
$ok = openssl_verify($data, $signature, $pub_key_id);
if ($ok == 1) {
echo "good";
} elseif ($ok == 0) {
echo "bad";
}
This returns always "bad".
Expected result:
----------------
"ok", but it's impossible :(
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=37820&edit=1