Bug->Doc #74715 [Opn->Ver]: openssl_pkcs12_export/export_to_file $args undocumented

From: Date: Thu, 08 Jun 2017 22:46:25 +0000
Subject: Bug->Doc #74715 [Opn->Ver]: openssl_pkcs12_export/export_to_file $args undocumented
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14766@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74715&edit=1 ID: 74715 Updated by: requinix@php.net Reported by: jelle at vdwaa dot nl -Summary: openssl_pkcs12_export allows invalid extracerts +Summary: openssl_pkcs12_export/export_to_file $args undocumented -Status: Open +Status: Verified -Type: Bug +Type: Documentation Problem Package: OpenSSL related Operating System: Arch Linux PHP Version: 7.2.0alpha1 Block user comment: N Private report: N New Comment: The array is checked for "friendly_name" (cert friendly name) and "extracerts" (cert authority chain) keys, whose values are used if present. Extra keys will be ignored. The friendly_name can be: - A string The extracerts can be: - An x509 resource (eg, from openssl_x509_read) - Anything accepted by openssl_x509_read, which is: * A string (or stringable object) filename prefixed with "file://" * A string (or stringable object) with the cert data - Or an array of any of the above On that note, openssl_x509_read doesn't have its $x509certdata documented either. Previous Comments: ------------------------------------------------------------------------ [2017-06-08 17:59:57] jelle at vdwaa dot nl Description: ------------ openssl_pkcs12_read returns true when "garbage" is inserted in the optional extra certs. No error is logged, while an error is expected. The test can be executed in php-src's (git repo) in ext/openssl/tests/ Test script: --------------- $p12 = "./p12_with_extra_certs.p12"; $pass = "qwerty"; openssl_pkcs12_read(file_get_contents($p12), $certs, $pass); //var_dump($certs); $ok = openssl_pkcs12_export($certs['cert'], $out, $certs['pkey'], $pass, array('blup')); var_dump($ok); Expected result: ---------------- Expect a warning to be throw about "blup" not being a valid X509 certificate. Actual result: -------------- bool(true) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74715&edit=1

« previous php.doc.bugs (#14766) next »