Laravel 5.6与TCPDF公钥加密实现求助(PKI新手)
Hey there! Since you're new to PKI and looking to add public key encryption to your Laravel 5.6 project using elibyy/tcpdf-laravel, let's break this down into actionable steps that fit your workflow:
First, you'll need a valid RSA public/private key pair. Use OpenSSL to generate them (most servers have this installed by default):
# Generate 2048-bit private key openssl genrsa -out private.key 2048 # Extract corresponding public key openssl rsa -in private.key -pubout -out public.key
Store these files in a secure directory in your project, like storage/app/keys/ (make sure to set proper file permissions so only your app can read them).
The elibyy/tcpdf-laravel package wraps TCPDF's core functionality, so you can directly use TCPDF's built-in public key encryption method. Here's how to integrate it into your existing workflow:
Replace AES Password Encryption with Public Key Encryption
If your current code looks something like this for password protection:
use PDF; $pdf = PDF::loadView('contracts.signed', $contractData); // Old AES 256 password encryption $pdf->setEncryption('user_pass', 'owner_pass', '', 0, 256); return $pdf->download('signed_contract.pdf');
Update it to use public key encryption instead:
use PDF; // Load your public key $publicKeyPath = storage_path('app/keys/public.key'); $publicKey = file_get_contents($publicKeyPath); // Prepare recipient data (you can add multiple recipients if needed) $recipients = [ [ 'certs' => $publicKey, 'name' => 'Contract Recipient' // Optional, for metadata ] ]; // Generate PDF from your contract view $pdf = PDF::loadView('contracts.signed', $contractData); // Enable public key encryption (leave password fields empty) $pdf->setEncryption( '', // User password (unused for public key encryption) '', // Owner password (unused for public key encryption) '', // Permissions (default is all restricted) 0, // Mode (0 = standard encryption) 256, // Encryption strength (256-bit AES) $recipients // Array of public key recipients ); // Output or save the encrypted PDF return $pdf->download('encrypted_signed_contract.pdf');
To tie this to your user's checkbox + completion action:
- Create a controller method that handles the form submission after the user signs and checks the box
- Validate that the checkbox is checked (e.g., using Laravel's validation rules)
- Run the PDF generation + encryption logic above
- Either save the encrypted PDF to your storage or send it directly to the user for download
- OpenSSL Requirement: Ensure your PHP environment has the OpenSSL extension enabled (it's usually enabled by default in Laravel setups, but you can verify with
php -m | grep openssl) - Decrypting the PDF: Only someone with the matching private key can decrypt the PDF. They can use tools like Adobe Acrobat or the following OpenSSL command:
openssl smime -decrypt -in encrypted_signed_contract.pdf -inkey private.key -out decrypted_contract.pdf - Permissions: If you want to allow limited actions (like printing) on the encrypted PDF, adjust the 3rd parameter of
setEncryption()with TCPDF's permission constants (e.g.,TCPDF_PERMISSION_PRINT)
Let me know if you hit any snags—happy to help work through specific issues!
内容的提问来源于stack exchange,提问作者Jonathon

