[php-src] PR #24060: Fix GH-20175: CertificateGenerator falls back to 1024-bit keys
| From: | bukka | Date: | Thu, 01 Oct 2026 20:55:02 +0000 |
| Subject: | [php-src] PR #24060: Fix GH-20175: CertificateGenerator falls back to 1024-bit keys | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39056@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24060
Author: bukka
CertificateGenerator::generateKey() called openssl_pkey_new() without the test config, so it
depended on the system openssl.cnf. When that file is missing, openssl_pkey_new() silently returns
false and openssl_csr_new() generates the key itself using default_bits from the supplied config,
which was 1024. OpenSSL 3.2+ defaults to security level 2 which rejects such keys, so TLS tests like
gh10495 fail.
Pass the test config explicitly so the explicit private_key_bits always applies, and bump the inline
default_bits to 2048 for consistency.
Closes GH-20176.