Bug #62050 [Csd]: Default CA certificates are not loaded
| From: | rdlowrey@php.net | Date: | Thu, 20 Feb 2014 01:37:41 +0000 |
| Subject: | Bug #62050 [Csd]: Default CA certificates are not loaded | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184373@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62050&edit=1
ID: 62050
Updated by: rdlowrey@php.net
Reported by: glenn at zewt dot org
Summary: Default CA certificates are not loaded
Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Linux
PHP Version: 5.4.3
Assigned To: rdlowrey
Block user comment: N
Private report: N
New Comment:
I've been contributing to PHP-src for about six weeks at this point. Let me apologize that this
wasn't fixed sooner. I only have 24 hours in the day and I've been spending a
disproportionate number of them working on the backlog of OpenSSL functionality. No one pays me to
work on PHP. If at any point you feel the progress isn't up to your standards feel free to do
what I did: start solving the problems and PRing fixes instead of complaining about them. Otherwise
take the self-righteousness on down the road.
Previous Comments:
------------------------------------------------------------------------
[2014-02-20 01:28:11] glenn at zewt dot org
Ignoring bug reports for a year and a half--especially detailed, security-related reports that
suggest a specific fix--is an effective way to discourage people from reporting bugs. Calling an
issue like this a "feature request" doesn't help, either.
------------------------------------------------------------------------
[2014-02-20 00:09:29] rdlowrey@php.net
Default cert locations are now loaded in the absence of a stream context specification or ini
directive (openssl.cafile/openssl.capath) as of PHP 5.6.
As this is more a feature request than an actual bug I'm closing the report. If the lack of
this functionality creates a serious problem for people in 5.4 and 5.5 I can look at possibly
backporting the feature once 5.6 is officially released.
Alternatively, you can try to hassle me on this bug report :)
------------------------------------------------------------------------
[2012-05-16 21:29:53] glenn at zewt dot org
Description:
------------
OpenSSL CA default certificates are not loaded. To make HTTPS certificate
verification work, I have to hardcode the path to where CA certs are on the
local system, eg:
$req = new HTTP_Request2('https://url',
HTTP_Request2::METHOD_GET,
array ("ssl_capath" => "/usr/lib/ssl/certs"));
This isn't portable, and it's very unobvious; it seems that some people "work
around" this by disabling certificate verification, which is bad. I don't know
if some distros patch around this problem, or if there's something else going on
for this not to happen to everybody; I'm hitting it on Debian testing and with
OpenSSL 1.0.1c.
In php_SSL_new_from_context, if cafile and capath are both NULL, it looks like
you only need to call SSL_CTX_set_default_verify_paths instead of
SSL_CTX_load_verify_locations. Don't call it if either are specified, so people
don't end up with certificates loaded when they explicitly want to load only
specific ones.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62050&edit=1