Doc #80078 [NEW]: openssl_dh_compute_key unknown parameters

From: Date: Tue, 08 Sep 2020 09:12:49 +0000
Subject: Doc #80078 [NEW]: openssl_dh_compute_key unknown parameters
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-17875@lists.php.net to get a copy of this message
From:             mfr64 at web dot de
Operating system: Windows
PHP version:      7.4.10
Package:          OpenSSL related
Bug Type:         Documentation Problem
Bug description:openssl_dh_compute_key unknown parameters

Description:
------------
With PHP 7.4.10 Development Server on Windows platform (Build:
C:\php-snap-build\php74\vc15\x64\obj\Release, extension=openssl enabled
within php.ini) I have this problem:

openssl_dh_compute_key apparently cannot deal with elliptic curve /
ECDH.

It could be I did not manage to find the trick as documentation/examples
are missing how to use with ECDH rather than RSA or DH keys.

openssl_dh_compute_key($pubkey, $dh_key) is checking parameter types. If
successful it does not return NULL (but FALSE). I never succeeded in
getting data from openssl_dh_compute_key other than FALSE or NULL. There
are no error messages.

What is wrong? Application of openssl_dh_compute_key or its
implementation?


Test script:
---------------
// $dh_key
// Secret brainpoolP384r1 key has been generated with:
//     $res = openssl_pkey_new($config);
//     $err = ! openssl_pkey_export($res, $privkey, "password", $config
);
//     file_put_contents($privkeyfile, $privkey)
//
// where $config = array("digest_alg" => "sha384",
//      "curve_name" => "brainpoolP384r1",
//      "private_key_type" => OPENSSL_KEYTYPE_EC,
//      "config"     => $configfile,  );
//
// For ECDH purpose following code reads it again in and provides
// $dh_key as a resource of type "OpenSSL key". This works well as
// binary private key can be obtained by this code:
//     $dh_key_det = openssl_pkey_get_details($dh_key);
//     $dh_cont = $dh_key_det["ec"]["d"];

$key = file_get_contents($privkeyfile);
$dh_key = openssl_get_privatekey($key, "password");


// $pubkey
// $cert is a certificate in PEM format.
// $pubkey is a string "-----BEGIN PUBLIC KEY----- MHow ... A4zQ==
-----END PUBLIC KEY----- "

$cert = file_get_contents($certfile);
$x509 = openssl_x509_read($cert);
$pubkeyid = openssl_get_publickey($x509);
$pubkeyid_det = openssl_pkey_get_details($pubkeyid);
$pubkey = $pubkeyid_det["key"];

// Now to the problem:
$res = openssl_dh_compute_key($pubkey, $dh_key);  // returning FALSE


Expected result:
----------------
1. Confirmation that openssl_dh_compute_key can handle ECDH, incl.
brainpoolP384r1 curve. If not, please add.
2. Information about how to set parameters correctly within ECDH
context, be it "brainpoolP384r1" or other curve.



Actual result:
--------------
openssl_dh_compute_key returning FALSE if parameters are correct type
but still wrong.
openssl_dh_compute_key returning NULL if parameters are not correct
type.

I never succeeded in getting data from openssl_dh_compute_key other than
FALSE or NULL. There are no error messages. Lack of documentation, lack
of examples.


-- 
Edit bug report at https://bugs.php.net/bug.php?id=80078&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=80078&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=80078&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=80078&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=80078&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=80078&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=80078&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=80078&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=80078&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=80078&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=80078&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80078&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=80078&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=80078&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=80078&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=80078&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=80078&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=80078&r=mysqlcfg


Thread (3 messages)

« previous php.doc.bugs (#17875) next »