PHP 8.6.0 Beta 1 is available for testing

openssl_cms_encrypt

(PHP 8)

openssl_cms_encryptCifra un mensaje CMS

Descripción

function openssl_cms_encrypt(
string $input_filename,
string $output_filename,
OpenSSLCertificate |array |string $certificate,
? array $headers,
int $flags = 0,
int $encoding = OPENSSL_ENCODING_SMIME ,
string |int $cipher_algo = OPENSSL_CIPHER_AES_128_CBC
): bool

Esta función cifra el contenido para uno o varios destinatarios, basado en los certificados que se le pasan.

Parámetros

input_filename

El fichero a cifrar.

output_filename

El fichero de salida.

certificate

Los destinatarios a cifrar.

headers

Las cabeceras a incluir al utilizar S/MIME.

flags

Los flag a pasar a CMS_sign.

encoding

Una codificación de salida. Una de las constantes OPENSSL_ENCODING_SMIME , OPENSSL_ENCODING_DER o OPENSSL_ENCODING_PEM .

cipher_algo

El cifrado a utilizar.

Valores devueltos

Esta función retorna true en caso de éxito o false si ocurre un error.

Historial de cambios

Versión Descripción
8.5.0 cipher_algo es ahora de tipo int o string . Anteriormente, era de tipo int .
8.1.0 El algoritmo de cifrado por omisión (cipher_algo) es ahora AES-128-CBC (OPENSSL_CIPHER_AES_128_CBC ). Anteriormente, se utilizaba PKCS7/CMS (OPENSSL_CIPHER_RC2_40 ).

Found A Problem?

Learn How To Improve This PageSubmit a Pull RequestReport a Bug
+add a note

User Contributed Notes 1 note

up
11
Sebastian
5 years ago
It took me a while to find out the correct way how to sign and encrypt data with these functions.
I needed that to communicate with German Health Insurance Providers as part of a DiGA. Maybe someone finds that useful.
<?php
function signAndEncrypt(string $rawData): string
{
 $tempDir = __DIR__ . '/tmp';
 $tempfileOriginal = tempnam($tempDir, 'original');
 $tempfileSigned = tempnam($tempDir, 'signed');
 $tempfileEncrypted = tempnam($tempDir, 'signedEncrypted');
 file_put_contents($tempfileOriginal, $rawData);
 // pick the correct certificate for the recipient
 $recipientsCertificateFile = __DIR__ . '/recipientsCertificate.pem';
 // -----BEGIN CERTIFICATE----- ...-----END CERTIFICATE-----
 $recipientsCertificate = file_get_contents($recipientsCertificateFile);
 // Certificate:
 // Data:
 // Version: 3 (0x2)...
 $myCertificate = file_get_contents(__DIR__ . '/my.crt');
 $myPrivateKey = openssl_pkey_get_private(
 // -----BEGIN RSA PRIVATE KEY----- ... -----END RSA PRIVATE KEY-----
 file_get_contents(__DIR__ . '/my.prv.key.pem')
 );
 openssl_cms_sign(
 input_filename: $tempfileOriginal,
 output_filename: $tempfileSigned,
 certificate: $myCertificate,
 private_key: $myPrivateKey,
 headers: [],
 encoding: OPENSSL_ENCODING_DER,
 );
 openssl_cms_encrypt(
 input_filename: $tempfileSigned,
 output_filename: $tempfileEncrypted,
 certificate: $recipientsCertificate,
 headers: [],
 flags: OPENSSL_CMS_BINARY | OPENSSL_CMS_NOSIGS | OPENSSL_CMS_NOVERIFY,
 encoding: OPENSSL_ENCODING_DER,
 cipher_algo: OPENSSL_CIPHER_AES_256_CBC
 );
 return file_get_contents($tempfileEncrypted);
}
+add a note

AltStyle によって変換されたページ (->オリジナル) /