We are still experiencing an intermittent Certificate Password Invalid issue in v3.0.0. We also observed it in earlier releases.
We suspect an OpenSSL error-queue handling issue.
We are seeing intermittent Certificate Password Invalid exceptions while signing PDFs with valid PKCS#12 certificate passwords.
The same password, left unchanged in the same browser field, could fail several times and then sign successfully.
Failures returned almost immediately, while successful signing took a few seconds.
Our logging showed that failed and successful attempts used identical inputs:
- same certificate byte length
- same certificate SHA-256
- same PDF byte length and SHA-256 for the same document version
- same password length
Workaround applied which works for us:
clear the OpenSSL error queue immediately before calling JSignPDF::sign()
private function clearOpenSslErrors(): array
{
$errors = [];
while (($error = openssl_error_string()) !== false) {
$errors[] = $error;
}
return $errors;
}
Possible patch the vendor library so pkcs12Read():
- Drain stale OpenSSL errors before
openssl_pkcs12_read(). If it fails, collect all resulting errors.
- If any collected error contains
digital envelope routines::unsupported, use the existing legacy PKCS#12 repack flow.
- After repacking, verify that
openssl_pkcs12_read() succeeds.
We are still experiencing an intermittent Certificate Password Invalid issue in v3.0.0. We also observed it in earlier releases.
We suspect an OpenSSL error-queue handling issue.
We are seeing intermittent Certificate Password Invalid exceptions while signing PDFs with valid PKCS#12 certificate passwords.
The same password, left unchanged in the same browser field, could fail several times and then sign successfully.
Failures returned almost immediately, while successful signing took a few seconds.
Our logging showed that failed and successful attempts used identical inputs:
Workaround applied which works for us:
clear the OpenSSL error queue immediately before calling JSignPDF::sign()
private function clearOpenSslErrors(): array
{
$errors = [];
}
Possible patch the vendor library so
pkcs12Read():openssl_pkcs12_read(). If it fails, collect all resulting errors.digital envelope routines::unsupported, use the existing legacy PKCS#12 repack flow.openssl_pkcs12_read()succeeds.