If you want to change the default private key size (1024) too something else you can use the following code:
<?php
$config = array('private_key_bits' => 512);
$privKey = openssl_pkey_new($config);
?>
Mind though that the minimum number of bits is 384. Any lower will trigger an error.
openssl_pkey_new
(PHP 4 >= 4.2.0, PHP 5)
openssl_pkey_new — Genera una clave privada nueva
Descripción
resource openssl_pkey_new
([ array $configargs
] )
openssl_pkey_new() genera un nuevo par calve privada y clave pública. El componente público de la clave se puede obtener usando openssl_pkey_get_public().
Note: Necesita tener instalado un openssl.cnf válido para que esta función opere correctamente. Vea las notas sobre la sección de instalación para más información.
Parámetros
- configargs
-
Se puede ajustar la generación de la clave (tal como especificando el número de bits) usando configargs. Véase openssl_csr_new() para más información acerca de configargs.
Valores devueltos
Devuelve un identificador de recurso para la clave privada si se tuvo éxito, o FALSE si se produjo un error.
jthijssen at notloxic dot nl
11-Feb-2011 02:17
Brad
02-Apr-2008 08:17
It's easier than all that, if you just want the keys:
<?php
// Create the keypair
$res=openssl_pkey_new();
// Get private key
openssl_pkey_export($res, $privkey);
// Get public key
$pubkey=openssl_pkey_get_details($res);
$pubkey=$pubkey["key"];
?>
NOSPAM dot alchaemist at hiperlinux dot com dot ar
30-May-2004 07:17
As you probably found, getting the public key is not as direct as you might think with this documentation.
You can easily get into messages like:
Warning: openssl_pkey_get_public(): Don't know how to get public key from this private key (the documentation lied) in D:\www\keys.php on line 4
The correct steps to get the whole thing seem to be these:
<?
$dn = array("countryName" => 'XX', "stateOrProvinceName" => 'State', "localityName" => 'SomewhereCity', "organizationName" => 'MySelf', "organizationalUnitName" => 'Whatever', "commonName" => 'mySelf', "emailAddress" => 'user@domain.com');
$privkeypass = '1234';
$numberofdays = 365;
$privkey = openssl_pkey_new();
$csr = openssl_csr_new($dn, $privkey);
$sscert = openssl_csr_sign($csr, null, $privkey, $numberofdays);
openssl_x509_export($sscert, $publickey);
openssl_pkey_export($privkey, $privatekey, $privkeypass);
openssl_csr_export($csr, $csrStr);
echo $privatekey; // Will hold the exported PriKey
echo $publickey; // Will hold the exported PubKey
echo $csrStr; // Will hold the exported Certificate
?>
Now all you need to do is to make some research on each individual function.
