Description
Description
openssl_sign() currently always performs the digest operation internally before signing the data.
This causes a problem when the input is already a precomputed digest.
For example, when a SHA-256 digest is passed to openssl_sign() together with OPENSSL_ALGO_SHA256, the digest is hashed again:
signature = sign(SHA256(precomputed_sha256_digest))
instead of signing the existing digest directly:
signature = sign(precomputed_sha256_digest)
As a result, PHP currently has no straightforward way to sign an already computed digest using ext/openssl.
Expected behavior
It should be possible to pass a precomputed digest to the OpenSSL extension and sign it directly without applying another hashing operation.
The same should be possible for verification of a signature over a precomputed digest.
Actual behavior
openssl_sign() combines hashing and signing. Therefore, when the caller already has the digest, an additional hashing operation is performed.
Additional information
OpenSSL provides lower-level APIs such as EVP_PKEY_sign() and EVP_PKEY_verify() that can operate on already prepared input.
PHP's OpenSSL extension currently does not expose an equivalent way to perform this operation.
PHP Version
Operating System
all
Description
Description
openssl_sign()currently always performs the digest operation internally before signing the data.This causes a problem when the input is already a precomputed digest.
For example, when a SHA-256 digest is passed to
openssl_sign()together withOPENSSL_ALGO_SHA256, the digest is hashed again:instead of signing the existing digest directly:
As a result, PHP currently has no straightforward way to sign an already computed digest using
ext/openssl.Expected behavior
It should be possible to pass a precomputed digest to the OpenSSL extension and sign it directly without applying another hashing operation.
The same should be possible for verification of a signature over a precomputed digest.
Actual behavior
openssl_sign()combines hashing and signing. Therefore, when the caller already has the digest, an additional hashing operation is performed.Additional information
OpenSSL provides lower-level APIs such as
EVP_PKEY_sign()andEVP_PKEY_verify()that can operate on already prepared input.PHP's OpenSSL extension currently does not expose an equivalent way to perform this operation.
PHP Version
Operating System
all