Req #65329 [Com]: PHP doesnot support TLSv1.1 and TLSv1.2

From: Date: Sat, 23 Nov 2013 05:40:15 +0000
Subject: Req #65329 [Com]: PHP doesnot support TLSv1.1 and TLSv1.2
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182898@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65329&edit=1 ID: 65329 Comment by: manu at netbsd dot org Reported by: yqbjtu at 163 dot com Summary: PHP doesnot support TLSv1.1 and TLSv1.2 Status: Analyzed Type: Feature/Change Request Package: OpenSSL related Operating System: All PHP Version: 5.5.1 Block user comment: N Private report: N New Comment: Um, I posted the patch too fast. It seems PHP is able to use TLSv1.2 without any modification. Just use a hostname prefixed with ssl:// instead of tls://. The former uses SSLv23_client_method() which is able to negociate TLSv1.2 (provided OpenSSL is recent enough) whereas the later uses TLSv1_client_method(), which does not negociate beyond TLSv1.0 Using ssl:// I have been able to have an unpatched PHP 5.3 client negociating ECDHE-RSA-AES256-GCM-SHA384, which as I understand is a TLSv1.2 only cipher. ssldump utility shows a clientHello version 3.3, which is TLSv1.2 IMO this request can be closed by just a documentation update. Previous Comments: ------------------------------------------------------------------------ [2013-11-23 04:56:17] manu at netbsd dot org This simple patch would do it: if OpenSSL supports TLSv1.2 it defines SSL_TXT_TLSV1_2. Just detect that and use TLSv1.2 instead of TLSv1.0 if possible: --- php-5.5.6/ext/openssl/xp_ssl.c.orig +++ php-5.5.6/ext/openssl/xp_ssl.c @@ -345,5 +345,9 @@ case STREAM_CRYPTO_METHOD_TLS_CLIENT: sslsock->is_client = 1; +#ifdef SSL_TXT_TLSV1_2 + method = TLSv1_2_client_method(); +#else method = TLSv1_client_method(); +#endif break; case STREAM_CRYPTO_METHOD_SSLv23_SERVER: @@ -366,5 +370,9 @@ case STREAM_CRYPTO_METHOD_TLS_SERVER: sslsock->is_client = 0; +#ifdef SSL_TXT_TLSV1_2 + method = TLSv1_2_server_method(); +#else method = TLSv1_server_method(); +#endif break; default: ------------------------------------------------------------------------ [2013-07-26 00:33:09] yohgaki@php.net TLSv1.0 is not good... PHP should support TLSv1.2 (and 1.1) ------------------------------------------------------------------------ [2013-07-25 03:39:01] yqbjtu at 163 dot com Description: ------------ When I used stream_socket_client method to connect a server,which enabled the TLSv1.2, my php have 100% CPU usage, but can't connect to the server. I checked the stream_get_transports();,found that PHP only supports the tcp [1] => udp [2] => ssl [3] => sslv3 [4] => sslv2 [5] => tls. I checked the source code, found that it does not support TLSv1.1 and TLSv1.2. I found it is very simple to support TLSv1.2, if possible, I can do it. ----------------------------the following is the supported protocols: C:\E\download\php-5.5.1-src\php-5.5.1-src\ext\openssl\openssl.c (5 hits) Line 1157: php_stream_xport_register("ssl", php_openssl_ssl_socket_factory TSRMLS_CC); Line 1158: php_stream_xport_register("sslv3", php_openssl_ssl_socket_factory TSRMLS_CC); Line 1160: php_stream_xport_register("sslv2", php_openssl_ssl_socket_factory TSRMLS_CC); Line 1162: php_stream_xport_register("tls", php_openssl_ssl_socket_factory TSRMLS_CC); Line 1165: php_stream_xport_register("tcp", php_openssl_ssl_socket_factory TSRMLS_CC); you can see in php_stream *php_openssl_ssl_socket_factory method (src\ext\openssl\xp_ssl.c) if (strncmp(proto, "ssl", protolen) == 0) { sslsock->enable_on_connect = 1; sslsock->method = STREAM_CRYPTO_METHOD_SSLv23_CLIENT; } else if (strncmp(proto, "sslv2", protolen) == 0) { #ifdef OPENSSL_NO_SSL2 php_error_docref(NULL TSRMLS_CC, E_WARNING, "SSLv2 support is not compiled into the OpenSSL library PHP is linked against"); return NULL; #else sslsock->enable_on_connect = 1; sslsock->method = STREAM_CRYPTO_METHOD_SSLv2_CLIENT; #endif } else if (strncmp(proto, "sslv3", protolen) == 0) { sslsock->enable_on_connect = 1; sslsock->method = STREAM_CRYPTO_METHOD_SSLv3_CLIENT; } else if (strncmp(proto, "tls", protolen) == 0) { sslsock->enable_on_connect = 1; sslsock->method = STREAM_CRYPTO_METHOD_TLS_CLIENT; } STREAM_CRYPTO_METHOD_TLS_CLIENT definition is as following. case STREAM_CRYPTO_METHOD_TLS_CLIENT: sslsock->is_client = 1; method = TLSv1_client_method(); break; ======================================== There are some methods in openssl openssl\ssl.h TLSv1_1_client_method(void); /* TLSv1.1 */ TLSv1_2_client_method(void); /* TLSv1.2 */ Expected result: ---------------- PHP does support TLSv1.1 and TLSv1.2 Actual result: -------------- PHP does not support TLSv1.1 and TLSv1.2 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=65329&edit=1

« previous php.bugs (#182898) next »