mirror of
https://github.com/danog/phpseclib.git
synced 2024-11-26 20:35:21 +01:00
Merge pull request #740 from terrafrost/x509-serialnumber-1.0
X509: use a random serial number for 1.0 branch * terrafrost/x509-serialnumber-1.0: X509: add a comment to explain the bitmask X509: move where Crypt/Random loading is done X509: use a random serial number
This commit is contained in:
commit
12ccc402b1
@ -3277,7 +3277,21 @@ class File_X509
|
||||
|
||||
$startDate = !empty($this->startDate) ? $this->startDate : @date('D, d M Y H:i:s O');
|
||||
$endDate = !empty($this->endDate) ? $this->endDate : @date('D, d M Y H:i:s O', strtotime('+1 year'));
|
||||
$serialNumber = !empty($this->serialNumber) ? $this->serialNumber : new Math_BigInteger();
|
||||
if (!empty($this->serialNumber)) {
|
||||
$serialNumber = $this->serialNumber;
|
||||
} else {
|
||||
if (!function_exists('crypt_random_string')) {
|
||||
include_once 'Crypt/Random.php';
|
||||
}
|
||||
/* "The serial number MUST be a positive integer"
|
||||
"Conforming CAs MUST NOT use serialNumber values longer than 20 octets."
|
||||
-- https://tools.ietf.org/html/rfc5280#section-4.1.2.2
|
||||
|
||||
for the integer to be positive the leading bit needs to be 0 hence the
|
||||
application of a bitmap
|
||||
*/
|
||||
$serialNumber = new Math_BigInteger(crypt_random_string(20) & ("\x7F" . str_repeat("\xFF", 19)), 256);
|
||||
}
|
||||
|
||||
$this->currentCert = array(
|
||||
'tbsCertificate' =>
|
||||
@ -3566,6 +3580,11 @@ class File_X509
|
||||
$crlNumber = $this->serialNumber;
|
||||
} else {
|
||||
$crlNumber = $this->getExtension('id-ce-cRLNumber');
|
||||
// "The CRL number is a non-critical CRL extension that conveys a
|
||||
// monotonically increasing sequence number for a given CRL scope and
|
||||
// CRL issuer. This extension allows users to easily determine when a
|
||||
// particular CRL supersedes another CRL."
|
||||
// -- https://tools.ietf.org/html/rfc5280#section-5.2.3
|
||||
$crlNumber = $crlNumber !== false ? $crlNumber->add(new Math_BigInteger(1)) : null;
|
||||
}
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user