Skip to main content

issuer.sign(subject) vs subject.signedBy(issuer) aka phpseclib vs the rest of the world

· 13 min read
phpseclib creator and maintainer

Most OOP X509 implementations do something roughly analogous to subject.signedBy(issuer). Since it doesn't make any sense for the (unsigned) subject to modify the issuer the two choices this leaves you with are: return the signed subject or modify the invoker (the subject) to include the signature.

phpseclib 4 flips this on its head. Instead of the invoker being the subject the invoker is the issuer. The subject is modified and the string that is the signature is returned. (Technically, the signature can be an array, as well, for EC / DSA objects with a signature format of Raw, but that's neither here nor there).

Special Thanks