Bug #62050 [Com]: Default CA certificates are not loaded
| From: | glenn at zewt dot org | Date: | Thu, 20 Feb 2014 01:28:12 +0000 |
| Subject: | Bug #62050 [Com]: Default CA certificates are not loaded | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184372@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62050&edit=1
ID: 62050
Comment by: glenn at zewt dot org
Reported by: glenn at zewt dot org
Summary: Default CA certificates are not loaded
Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Linux
PHP Version: 5.4.3
Assigned To: rdlowrey
Block user comment: N
Private report: N
New Comment:
Ignoring bug reports for a year and a half--especially detailed, security-related reports that
suggest a specific fix--is an effective way to discourage people from reporting bugs. Calling an
issue like this a "feature request" doesn't help, either.
Previous Comments:
------------------------------------------------------------------------
[2014-02-20 00:09:29] rdlowrey@php.net
Default cert locations are now loaded in the absence of a stream context specification or ini
directive (openssl.cafile/openssl.capath) as of PHP 5.6.
As this is more a feature request than an actual bug I'm closing the report. If the lack of
this functionality creates a serious problem for people in 5.4 and 5.5 I can look at possibly
backporting the feature once 5.6 is officially released.
Alternatively, you can try to hassle me on this bug report :)
------------------------------------------------------------------------
[2012-05-16 21:29:53] glenn at zewt dot org
Description:
------------
OpenSSL CA default certificates are not loaded. To make HTTPS certificate
verification work, I have to hardcode the path to where CA certs are on the
local system, eg:
$req = new HTTP_Request2('https://url',
HTTP_Request2::METHOD_GET,
array ("ssl_capath" => "/usr/lib/ssl/certs"));
This isn't portable, and it's very unobvious; it seems that some people "work
around" this by disabling certificate verification, which is bad. I don't know
if some distros patch around this problem, or if there's something else going on
for this not to happen to everybody; I'm hitting it on Debian testing and with
OpenSSL 1.0.1c.
In php_SSL_new_from_context, if cafile and capath are both NULL, it looks like
you only need to call SSL_CTX_set_default_verify_paths instead of
SSL_CTX_load_verify_locations. Don't call it if either are specified, so people
don't end up with certificates loaded when they explicitly want to load only
specific ones.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62050&edit=1