Req #65329 [Com]: PHP doesnot support TLSv1.1 and TLSv1.2
| From: | manu at netbsd dot org | Date: | Sat, 23 Nov 2013 05:40:15 +0000 |
| Subject: | Req #65329 [Com]: PHP doesnot support TLSv1.1 and TLSv1.2 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182898@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65329&edit=1
ID: 65329
Comment by: manu at netbsd dot org
Reported by: yqbjtu at 163 dot com
Summary: PHP doesnot support TLSv1.1 and TLSv1.2
Status: Analyzed
Type: Feature/Change Request
Package: OpenSSL related
Operating System: All
PHP Version: 5.5.1
Block user comment: N
Private report: N
New Comment:
Um, I posted the patch too fast.
It seems PHP is able to use TLSv1.2 without any modification. Just use a hostname prefixed with
ssl:// instead of tls://. The former uses SSLv23_client_method() which is able to negociate TLSv1.2
(provided OpenSSL is recent enough) whereas the later uses TLSv1_client_method(), which does not
negociate beyond TLSv1.0
Using ssl:// I have been able to have an unpatched PHP 5.3 client negociating
ECDHE-RSA-AES256-GCM-SHA384, which as I understand is a TLSv1.2 only cipher. ssldump utility shows a
clientHello version 3.3, which is TLSv1.2
IMO this request can be closed by just a documentation update.
Previous Comments:
------------------------------------------------------------------------
[2013-11-23 04:56:17] manu at netbsd dot org
This simple patch would do it: if OpenSSL supports TLSv1.2 it defines SSL_TXT_TLSV1_2. Just detect
that and use TLSv1.2 instead of TLSv1.0 if possible:
--- php-5.5.6/ext/openssl/xp_ssl.c.orig
+++ php-5.5.6/ext/openssl/xp_ssl.c
@@ -345,5 +345,9 @@
case STREAM_CRYPTO_METHOD_TLS_CLIENT:
sslsock->is_client = 1;
+#ifdef SSL_TXT_TLSV1_2
+ method = TLSv1_2_client_method();
+#else
method = TLSv1_client_method();
+#endif
break;
case STREAM_CRYPTO_METHOD_SSLv23_SERVER:
@@ -366,5 +370,9 @@
case STREAM_CRYPTO_METHOD_TLS_SERVER:
sslsock->is_client = 0;
+#ifdef SSL_TXT_TLSV1_2
+ method = TLSv1_2_server_method();
+#else
method = TLSv1_server_method();
+#endif
break;
default:
------------------------------------------------------------------------
[2013-07-26 00:33:09] yohgaki@php.net
TLSv1.0 is not good...
PHP should support TLSv1.2 (and 1.1)
------------------------------------------------------------------------
[2013-07-25 03:39:01] yqbjtu at 163 dot com
Description:
------------
When I used stream_socket_client method to connect a server,which enabled the TLSv1.2, my php have
100% CPU usage, but can't connect to the server. I checked the stream_get_transports();,found
that PHP only supports the tcp [1] => udp [2] => ssl [3] => sslv3 [4] => sslv2 [5] =>
tls.
I checked the source code, found that it does not support TLSv1.1 and TLSv1.2.
I found it is very simple to support TLSv1.2, if possible, I can do it.
----------------------------the following is the supported protocols:
C:\E\download\php-5.5.1-src\php-5.5.1-src\ext\openssl\openssl.c (5 hits)
Line 1157: php_stream_xport_register("ssl", php_openssl_ssl_socket_factory TSRMLS_CC);
Line 1158: php_stream_xport_register("sslv3", php_openssl_ssl_socket_factory TSRMLS_CC);
Line 1160: php_stream_xport_register("sslv2", php_openssl_ssl_socket_factory TSRMLS_CC);
Line 1162: php_stream_xport_register("tls", php_openssl_ssl_socket_factory TSRMLS_CC);
Line 1165: php_stream_xport_register("tcp", php_openssl_ssl_socket_factory TSRMLS_CC);
you can see
in php_stream *php_openssl_ssl_socket_factory method (src\ext\openssl\xp_ssl.c)
if (strncmp(proto, "ssl", protolen) == 0) {
sslsock->enable_on_connect = 1;
sslsock->method = STREAM_CRYPTO_METHOD_SSLv23_CLIENT;
} else if (strncmp(proto, "sslv2", protolen) == 0) {
#ifdef OPENSSL_NO_SSL2
php_error_docref(NULL TSRMLS_CC, E_WARNING, "SSLv2 support is not compiled into the OpenSSL
library PHP is linked against");
return NULL;
#else
sslsock->enable_on_connect = 1;
sslsock->method = STREAM_CRYPTO_METHOD_SSLv2_CLIENT;
#endif
} else if (strncmp(proto, "sslv3", protolen) == 0) {
sslsock->enable_on_connect = 1;
sslsock->method = STREAM_CRYPTO_METHOD_SSLv3_CLIENT;
} else if (strncmp(proto, "tls", protolen) == 0) {
sslsock->enable_on_connect = 1;
sslsock->method = STREAM_CRYPTO_METHOD_TLS_CLIENT;
}
STREAM_CRYPTO_METHOD_TLS_CLIENT definition is as following.
case STREAM_CRYPTO_METHOD_TLS_CLIENT:
sslsock->is_client = 1;
method = TLSv1_client_method();
break;
========================================
There are some methods in openssl openssl\ssl.h
TLSv1_1_client_method(void); /* TLSv1.1 */
TLSv1_2_client_method(void); /* TLSv1.2 */
Expected result:
----------------
PHP does support TLSv1.1 and TLSv1.2
Actual result:
--------------
PHP does not support TLSv1.1 and TLSv1.2
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65329&edit=1