@@ -581,6 +581,15 @@ X509 *php_openssl_x509_from_zval(
581581 return cert ;
582582}
583583
584+ static void php_openssl_fingerprint_warn (php_stream * stream , zend_enum_StreamErrorCode code , const char * msg )
585+ {
586+ if (stream != NULL ) {
587+ php_stream_error (stream , NULL , E_WARNING , true, code , "%s" , msg );
588+ } else {
589+ php_error_docref (NULL , E_WARNING , "%s" , msg );
590+ }
591+ }
592+
584593zend_string * php_openssl_x509_fingerprint (X509 * peer , const char * method , bool raw , php_stream * stream )
585594{
586595 unsigned char md [EVP_MAX_MD_SIZE ];
@@ -589,19 +598,20 @@ zend_string* php_openssl_x509_fingerprint(X509 *peer, const char *method, bool r
589598 zend_string * ret ;
590599
591600 if (!(mdtype = php_openssl_get_evp_md_by_name (method ))) {
592- if (stream != NULL ) {
593- php_stream_warn (stream , Generic , "Unknown digest algorithm" );
594- } else {
595- php_error_docref (NULL , E_WARNING , "Unknown digest algorithm" );
596- }
601+ php_openssl_fingerprint_warn (stream , PHP_STREAM_EC (Generic ), "Unknown digest algorithm" );
597602 return NULL ;
598603 } else if (!X509_digest (peer , mdtype , md , & n )) {
604+ bool is_xof = EVP_MD_flags (mdtype ) & EVP_MD_FLAG_XOF ;
599605 php_openssl_release_evp_md (mdtype );
600606 php_openssl_store_errors ();
601- if (stream != NULL ) {
602- php_stream_warn (stream , EncodingFailed , "Could not generate signature" );
607+ if (is_xof ) {
608+ php_openssl_fingerprint_warn (
609+ stream ,
610+ PHP_STREAM_EC (Generic ),
611+ "Unsupported digest algorithm: output length must be specified"
612+ );
603613 } else {
604- php_error_docref ( NULL , E_WARNING , "Could not generate signature" );
614+ php_openssl_fingerprint_warn ( stream , PHP_STREAM_EC ( EncodingFailed ) , "Could not generate signature" );
605615 }
606616 return NULL ;
607617 }
0 commit comments