Skip to content

Fix GH-21545: openssl_x509_parse() validTo_time_t after the year 3000 - #24058

Open
bukka wants to merge 1 commit into
php:PHP-8.5from
bukka:openssl_gh21545_x509_parse_valit_time
Open

bukka wants to merge 1 commit into
php:PHP-8.5from
bukka:openssl_gh21545_x509_parse_valit_time

Conversation

@bukka

@bukka bukka commented Oct 1, 2026

Copy link
Copy Markdown
Member

The ASN.1 time was converted to a timestamp with mktime() and a manual time zone correction. MSVC's 64-bit mktime() cannot represent dates after 23:59:59 on 31 December 3000 UTC and returns -1, which then had the local time zone adjustment added to it, producing values like 7199 or 32399.

Decode the string with ASN1_TIME_to_tm() and compute the timestamp directly from the UTC civil date, so the result no longer depends on the C library's mktime() range or on the local time zone.

Closes GH-21545

The ASN.1 time was converted to a timestamp with mktime() and a manual
time zone correction. MSVC's 64-bit mktime() cannot represent dates after
23:59:59 on 31 December 3000 UTC and returns -1, which then had the local
time zone adjustment added to it, producing values like 7199 or 32399.

Decode the string with ASN1_TIME_to_tm() and compute the timestamp
directly from the UTC civil date, so the result no longer depends on the
C library's mktime() range or on the local time zone.

Closes phpGH-21545
@bukka

bukka commented Oct 1, 2026 •

Copy link
Copy Markdown
Member Author

I target just 8.5+ as I can't be bothered to deal with conflict for this sort of "not real" issue (who would be using certs valid longer than year 3000...? :) )

@LamentXU123 LamentXU123 left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks more sensible than my previous attempt.


if (ASN1_STRING_type(timestr) == V_ASN1_GENERALIZEDTIME && timestr_len < 15) {
/* Validates the string and fills in the broken-down time in UTC. */
if (!ASN1_TIME_to_tm(timestr, &thetime)) {

@LamentXU123 LamentXU123 Oct 2, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While at it, why not use ASN1_TIME_diff for the whole algo?
https://manpages.opensuse.org/Leap-15.6/openssl-3-doc/ASN1_TIME_diff.33ssl.en.html
So you don't need to maintain the date algo yourself. But at the cost that there might be one more allocation/free for ASN1_TIME in each call.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PHP OpenSSL ext: openssl_x509_parse miscalculates validTo_time_t for far-future certificate dates

2 participants