[php-src] PR #24096: ext/openssl: Support detached signatures with S/MIME encoding
| From: | adapik | Date: | Sat, 03 Oct 2026 14:20:46 +0000 |
| Subject: | [php-src] PR #24096: ext/openssl: Support detached signatures with S/MIME encoding | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39105@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24096
Author: adapik
openssl_cms_sign(): support detached signatures with S/MIME encoding
OPENSSL_CMS_DETACHED with the default S/MIME encoding was rejected with a warning. But
it works perfectly in openssl:
openssl cms -sign -in msg.txt -signer cert.pem -inkey key.pem -out signed.eml
It can work in PHP as well: this PR adds CMS_STREAM (as the OpenSSL CLI does) makes
SMIME_write_CMS() produce a multipart/signed message.
openssl_cms_verify() already reads such messages. Only its warning for a separate
$signature_filename with S/MIME is reworded, as it no longer claims that detached
signatures are impossible.