Skip to content

Intermittent false Certificate Password Invalid. for legacy PKCS#12 certificates #66

Description

@vkywalker

We are still experiencing an intermittent Certificate Password Invalid issue in v3.0.0. We also observed it in earlier releases.

We suspect an OpenSSL error-queue handling issue.

We are seeing intermittent Certificate Password Invalid exceptions while signing PDFs with valid PKCS#12 certificate passwords.
The same password, left unchanged in the same browser field, could fail several times and then sign successfully.
Failures returned almost immediately, while successful signing took a few seconds.

Our logging showed that failed and successful attempts used identical inputs:

  • same certificate byte length
  • same certificate SHA-256
  • same PDF byte length and SHA-256 for the same document version
  • same password length

Workaround applied which works for us:
clear the OpenSSL error queue immediately before calling JSignPDF::sign()

private function clearOpenSslErrors(): array
{
$errors = [];

while (($error = openssl_error_string()) !== false) {
    $errors[] = $error;
}

return $errors;

}

Possible patch the vendor library so pkcs12Read():

  1. Drain stale OpenSSL errors before openssl_pkcs12_read(). If it fails, collect all resulting errors.
  2. If any collected error contains digital envelope routines::unsupported, use the existing legacy PKCS#12 repack flow.
  3. After repacking, verify that openssl_pkcs12_read() succeeds.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions