[php-src] Issue #23422: openssl_sign() cannot sign a precomputed digest

[email protected] (timo-poppinga)
Newsgroups php.bugs
Message-ID <[email protected]>
Issue: https://github.com/php/php-src/issues/23422
Author: timo-poppinga

### Description

## Description

`openssl_sign()` currently always performs the digest operation internally before signing the data.

This causes a problem when the input is already a precomputed digest.

For example, when a SHA-256 digest is passed to `openssl_sign()` together with `OPENSSL_ALGO_SHA256`, the digest is hashed again:

    signature = sign(SHA256(precomputed_sha256_digest))

instead of signing the existing digest directly:

    signature = sign(precomputed_sha256_digest)

As a result, PHP currently has no straightforward way to sign an already computed digest using `ext/openssl`.

## Expected behavior

It should be possible to pass a precomputed digest to the OpenSSL extension and sign it directly without applying another hashing operation.

The same should be possible for verification of a signature over a precomputed digest.

## Actual behavior

`openssl_sign()` combines hashing and signing. Therefore, when the caller already has the digest, an additional hashing operation is performed.

## Additional information

OpenSSL provides lower-level APIs such as `EVP_PKEY_sign()` and `EVP_PKEY_verify()` that can operate on already prepared input.

PHP's OpenSSL extension currently does not expose an equivalent way to perform this operation.

### PHP Version

```plain
PHP 8.5
```

### Operating System

all
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.