Doc #74715 [Ver->Csd]: openssl_pkcs12_export/export_to_file $args undocumented
| From: | mjones@php.net | Date: | Fri, 03 Nov 2017 22:13:55 +0000 |
| Subject: | Doc #74715 [Ver->Csd]: openssl_pkcs12_export/export_to_file $args undocumented | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-15217@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74715&edit=1
ID: 74715
Updated by: mjones@php.net
Reported by: jelle at vdwaa dot nl
Summary: openssl_pkcs12_export/export_to_file $args
undocumented
-Status: Verified
+Status: Closed
Type: Documentation Problem
Package: OpenSSL related
Operating System: Arch Linux
PHP Version: 7.2.0alpha1
-Assigned To:
+Assigned To: mjones
Block user comment: N
Private report: N
New Comment:
documented openssl_x509_read $x509certdata
and for openssl_pkcs12_export documented that extra keys will be ignored.
commit r343361
Previous Comments:
------------------------------------------------------------------------
[2017-11-03 22:12:45] mjones@php.net
Automatic comment from SVN on behalf of mjones
Revision: http://svn.php.net/viewvc/?view=revision&revision=343361
Log: Fix bug #74715: openssl_pkcs12_export documentation
------------------------------------------------------------------------
[2017-06-08 22:46:22] requinix@php.net
The array is checked for "friendly_name" (cert friendly name) and "extracerts"
(cert authority chain) keys, whose values are used if present. Extra keys will be ignored.
The friendly_name can be:
- A string
The extracerts can be:
- An x509 resource (eg, from openssl_x509_read)
- Anything accepted by openssl_x509_read, which is:
* A string (or stringable object) filename prefixed with "file://"
* A string (or stringable object) with the cert data
- Or an array of any of the above
On that note, openssl_x509_read doesn't have its $x509certdata documented either.
------------------------------------------------------------------------
[2017-06-08 17:59:57] jelle at vdwaa dot nl
Description:
------------
openssl_pkcs12_read returns true when "garbage" is inserted in the optional extra certs.
No error is logged, while an error is expected. The test can be executed in php-src's (git
repo) in ext/openssl/tests/
Test script:
---------------
$p12 = "./p12_with_extra_certs.p12";
$pass = "qwerty";
openssl_pkcs12_read(file_get_contents($p12), $certs, $pass);
//var_dump($certs);
$ok = openssl_pkcs12_export($certs['cert'], $out, $certs['pkey'], $pass,
array('blup'));
var_dump($ok);
Expected result:
----------------
Expect a warning to be throw about "blup" not being a valid X509 certificate.
Actual result:
--------------
bool(true)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74715&edit=1