Bug #62050 [Com]: Default CA certificates are not loaded

From: Date: Thu, 20 Feb 2014 01:28:12 +0000
Subject: Bug #62050 [Com]: Default CA certificates are not loaded
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184372@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62050&edit=1 ID: 62050 Comment by: glenn at zewt dot org Reported by: glenn at zewt dot org Summary: Default CA certificates are not loaded Status: Closed Type: Bug Package: OpenSSL related Operating System: Linux PHP Version: 5.4.3 Assigned To: rdlowrey Block user comment: N Private report: N New Comment: Ignoring bug reports for a year and a half--especially detailed, security-related reports that suggest a specific fix--is an effective way to discourage people from reporting bugs. Calling an issue like this a "feature request" doesn't help, either. Previous Comments: ------------------------------------------------------------------------ [2014-02-20 00:09:29] rdlowrey@php.net Default cert locations are now loaded in the absence of a stream context specification or ini directive (openssl.cafile/openssl.capath) as of PHP 5.6. As this is more a feature request than an actual bug I'm closing the report. If the lack of this functionality creates a serious problem for people in 5.4 and 5.5 I can look at possibly backporting the feature once 5.6 is officially released. Alternatively, you can try to hassle me on this bug report :) ------------------------------------------------------------------------ [2012-05-16 21:29:53] glenn at zewt dot org Description: ------------ OpenSSL CA default certificates are not loaded. To make HTTPS certificate verification work, I have to hardcode the path to where CA certs are on the local system, eg: $req = new HTTP_Request2('https://url', HTTP_Request2::METHOD_GET, array ("ssl_capath" => "/usr/lib/ssl/certs")); This isn't portable, and it's very unobvious; it seems that some people "work around" this by disabling certificate verification, which is bad. I don't know if some distros patch around this problem, or if there's something else going on for this not to happen to everybody; I'm hitting it on Debian testing and with OpenSSL 1.0.1c. In php_SSL_new_from_context, if cafile and capath are both NULL, it looks like you only need to call SSL_CTX_set_default_verify_paths instead of SSL_CTX_load_verify_locations. Don't call it if either are specified, so people don't end up with certificates loaded when they explicitly want to load only specific ones. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=62050&edit=1

« previous php.bugs (#184372) next »