Skip to content

Fix GH-20175: CertificateGenerator falls back to 1024-bit keys - #24060

Open
bukka wants to merge 1 commit into
php:PHP-8.4from
bukka:openssl_cert_generator_config
Open

bukka wants to merge 1 commit into
php:PHP-8.4from
bukka:openssl_cert_generator_config

Conversation

@bukka

@bukka bukka commented Oct 1, 2026

Copy link
Copy Markdown
Member

CertificateGenerator::generateKey() called openssl_pkey_new() without the test config, so it depended on the system openssl.cnf. When that file is missing, openssl_pkey_new() silently returns false and openssl_csr_new() generates the key itself using default_bits from the supplied config, which was 1024. OpenSSL 3.2+ defaults to security level 2 which rejects such keys, so TLS tests like gh10495 fail.

Pass the test config explicitly so the explicit private_key_bits always applies, and bump the inline default_bits to 2048 for consistency.

Closes GH-20176.

CertificateGenerator::generateKey() called openssl_pkey_new() without the
test config, so it depended on the system openssl.cnf. When that file is
missing, openssl_pkey_new() silently returns false and openssl_csr_new()
generates the key itself using default_bits from the supplied config,
which was 1024. OpenSSL 3.2+ defaults to security level 2 which rejects
such keys, so TLS tests like gh10495 fail.

Pass the test config explicitly so the explicit private_key_bits always
applies, and bump the inline default_bits to 2048 for consistency.

Closes phpGH-20176.

Co-authored-by: velemas <velemas@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant