openssl_pkey_export() Fails Under OpenSSL 3.x FIPS Mode (due to legacy PEM encryption APIs)
@bukka is already working on this.
Since May 3, 2025.
Assessment
This issue has not been assessed yet.
Description
Description
Summary
When using PHP with OpenSSL 3.x in FIPS mode (as enabled by default in certain environments such as Amazon Linux 2023), the openssl_pkey_export() function fails when a passphrase is provided.
This is due to the use of legacy OpenSSL APIs (PEM_write_bio_PrivateKey() → PEM_write_bio_PrivateKey_traditional() → EVP_CipherInit_ex()), which are not FIPS-compliant in OpenSSL 3.x.
Affected:
PHP 8.1 – 8.4
OpenSSL 3.x in FIPS mode
PHP’s built-in openssl extension
openssl_pkey_export($key, $out, $passphrase) when $passphrase is provided
Reproduction
<?php
$privateKey = openssl_pkey_new([
"private_key_bits" => 2048,
"private_key_type" => OPENSSL_KEYTYPE_RSA,
]);
openssl_pkey_export($privateKey, $out, 'testpass');
When run under OpenSSL 3.x with FIPS enabled, the call fails with:
error:0308010C:digital envelope routines::unsupported
Root Cause (maybe?)
Internally, PHP uses:
openssl_pkey_export()
↓
PEM_write_bio_PrivateKey()
↓
PEM_write_bio_PrivateKey_traditional()
↓
PEM_ASN1_write_bio()
↓
EVP_CipherInit_ex() (manual cipher setup)
In OpenSSL 3 FIPS mode, manual cipher encryption is disallowed.
Only provider-based encryption (via OSSL_ENCODER, etc.) is allowed.
This behavior is documented in the OpenSSL 3.x migration guide and FIPS module guide:
Applications should no longer rely on implicit fetches of algorithms
or manually configure cipher contexts outside the provider framework.
Expected Behavior
If the system is in FIPS mode and the passphrase is provided,
openssl_pkey_export() should either:
Properly export the key using a FIPS-compliant provider mechanism (e.g., via OSSL_ENCODER)
Or fail with a clear message that encrypted exports are not supported under current conditions
As a note, my openssl is configured properly and I can generate a private key with a passphrase via the command line. Also, if you leave the passphrase out of the call openssl_pkey_export() it does work without encryption.
PHP Version
PHP 8.1.32 (cli) (built: Mar 11 2025 22:09:20) (NTS gcc x86_64)
Copyright (c) The PHP Group
Zend Engine v4.1.32, Copyright (c) Zend Technologies
with Zend OPcache v8.1.32, Copyright (c), by Zend Technologies
Operating System
No response
- Dominant language
- C
- Stars
- 40.4k
- Forks
- 8.2k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 103
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from php/php-src
-
Bug SAPI: cli_server Status: Verified
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Bug Status: Needs Triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
Bug Status: Needs Triage
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
Bug Status: Needs Triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Bug Category: Tests Status: Verified
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Similar issues
-
[adam] AdamNet network read doesn't cap to MAX_ADAM_PACKET_LEN, overflows client receive buffers Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
FujiNetWIFI/fujinet-firmware#1649 · 2 comments ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
HarbourMasters/Shipwright#7229 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
riscv-software-src/riscv-isa-sim#2435 · 1 comment ·
-
bug Self Built Image SNAPSHOT Supported Device target/ramips
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100