Commit 9cce6468a2c for php
commit 9cce6468a2c9fbfcbe11f2d4a971079d9632778d
Author: Alexander Danilov <10532067+adapik@users.noreply.github.com>
Date: Thu Oct 1 19:18:06 2026 +0300
openssl_sign - restore default salt length without passing salt_length parameter (#24033)
diff --git a/NEWS b/NEWS
index b91a71a3f18..1bfc1a6be15 100644
--- a/NEWS
+++ b/NEWS
@@ -61,6 +61,8 @@ PHP NEWS
. Fixed stream_socket_enable_crypto() leaving the socket non-blocking
after a handshake timeout. (Ilia Alshanetsky)
. Fix memory leak by doing early salt validation. (adapik)
+ . Fixed openssl_sign() using the maximum RSA-PSS salt length by default
+ instead of the OpenSSL default. (adapik)
- PCNTL:
. Fixed pcntl_signal_dispatch() dropping the queued signals when it runs while
diff --git a/ext/openssl/openssl.c b/ext/openssl/openssl.c
index 6ec8a11734a..7123bf7f393 100644
--- a/ext/openssl/openssl.c
+++ b/ext/openssl/openssl.c
@@ -4515,6 +4515,11 @@ static zend_result php_openssl_setup_rsa_pss_salt_length(EVP_PKEY_CTX *pctx, EVP
return SUCCESS;
}
+ /* For AUTO, keep the OpenSSL default salt length. */
+ if (salt_length == RSA_PSS_SALTLEN_AUTO) {
+ return SUCCESS;
+ }
+
/* Only apply to RSA keys */
if (EVP_PKEY_base_id(pkey) != EVP_PKEY_RSA && EVP_PKEY_base_id(pkey) != EVP_PKEY_RSA_PSS) {
return SUCCESS;
diff --git a/ext/openssl/tests/openssl_sign_pss_default_salt_length.phpt b/ext/openssl/tests/openssl_sign_pss_default_salt_length.phpt
new file mode 100644
index 00000000000..6042371c28c
--- /dev/null
+++ b/ext/openssl/tests/openssl_sign_pss_default_salt_length.phpt
@@ -0,0 +1,20 @@
+--TEST--
+openssl_sign() with RSA-PSS uses the digest length as the default salt length (OpenSSL >= 3.1)
+--EXTENSIONS--
+openssl
+--SKIPIF--
+<?php
+if (OPENSSL_VERSION_NUMBER < 0x30100000) die('skip For OpenSSL >= 3.1');
+?>
+--FILE--
+<?php
+$data = "Testing openssl_sign() with RSA-PSS";
+$privkey = "file://" . __DIR__ . "/private_rsa_1024.key";
+$pubkey = "file://" . __DIR__ . "/public.key";
+
+var_dump(openssl_sign($data, $sign, $privkey, OPENSSL_ALGO_SHA256, OPENSSL_PKCS1_PSS_PADDING));
+var_dump(openssl_verify($data, $sign, $pubkey, OPENSSL_ALGO_SHA256, OPENSSL_PKCS1_PSS_PADDING, OPENSSL_RSA_PSS_SALTLEN_DIGEST));
+?>
+--EXPECT--
+bool(true)
+int(1)