Windows下PHP5.6升级至8.2后openssl_pkcs12_read报错求解决方案
解决Windows下PHP 8.2中openssl_pkcs12_read报digital envelope routines::unsupported的问题
错误原因
PHP 8.2依赖的OpenSSL版本默认禁用了MD5、SHA1等老旧加密算法,而你当前使用的PK12证书是基于这些旧算法生成的,导致openssl_pkcs12_read无法正常解析文件。
解决方法
方法1:修改OpenSSL配置启用旧算法(临时兼容)
- 找到PHP安装目录下的
extras/ssl/openssl.cnf文件,若没有可从OpenSSL官方渠道获取一份基础配置文件。 - 打开配置文件,在开头添加以下内容:
[openssl_init] openssl_conf = default_conf [default_conf] ssl_conf = ssl_sect [ssl_sect] system_default = system_default_sect [system_default_sect] MinProtocol = TLSv1.2 CipherString = DEFAULT@SECLEVEL=1
- 修改PHP的
php.ini文件,明确指定openssl.cnf的路径:
openssl.conf = "C:/你的PHP安装路径/extras/ssl/openssl.cnf"
- 重启PHP相关服务(如IIS、Apache或PHP-FPM)。
方法2:重新生成兼容新算法的PK12文件(推荐)
使用OpenSSL命令重新导出PK12证书,采用现代加密标准:
openssl pkcs12 -export -in 你的证书文件.pem -inkey 你的密钥文件.pem -out new_pass.com.testpass.p12 -name "APNs Cert" -certfile 根证书.pem -passout pass:MyPassword -iter 2000 -macalg SHA256 -CSP "Microsoft RSA SChannel Cryptographic Provider"
参数说明:
-iter 2000:增加迭代次数提升证书安全性-macalg SHA256:使用SHA256作为消息认证算法-CSP:指定Windows兼容的加密服务提供者
生成新证书后,替换代码中的文件路径即可正常运行原逻辑。
方法3:代码中动态加载自定义OpenSSL配置(灵活方案)
在调用openssl_pkcs12_read前,临时加载兼容配置:
// 定义兼容旧算法的OpenSSL配置 $customOpenSSLConfig = <<<EOF [openssl_init] openssl_conf = default_conf [default_conf] ssl_conf = ssl_sect [ssl_sect] system_default = system_default_sect [system_default_sect] MinProtocol = TLSv1.2 CipherString = DEFAULT@SECLEVEL=1 EOF; // 创建临时配置文件 $tempConfFile = tempnam(sys_get_temp_dir(), 'openssl_'); file_put_contents($tempConfFile, $customOpenSSLConfig); // 让OpenSSL使用临时配置 openssl_config($tempConfFile); // 原业务代码 $p12_filename = "..\\path\\to\\pass.com.testpass.p12"; $p12data = file_get_contents($p12_filename); $p12Password = 'MyPassword'; $rp12 = array(); $rc = openssl_pkcs12_read($p12data, $rp12, $p12Password); $cert_data = $rp12['cert']; $cert_key = $rp12['pkey']; // 清理临时文件 unlink($tempConfFile);
错误验证
若仍有问题,可添加错误输出排查细节:
if (!$rc) { echo openssl_error_string(); }
内容的提问来源于stack exchange,提问作者Barny
相关产品推荐
相关产品推荐

