Bug #62050 [Csd]: Default CA certificates are not loaded

From: Date: Thu, 20 Feb 2014 01:37:41 +0000
Subject: Bug #62050 [Csd]: Default CA certificates are not loaded
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184373@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62050&edit=1 ID: 62050 Updated by: rdlowrey@php.net Reported by: glenn at zewt dot org Summary: Default CA certificates are not loaded Status: Closed Type: Bug Package: OpenSSL related Operating System: Linux PHP Version: 5.4.3 Assigned To: rdlowrey Block user comment: N Private report: N New Comment: I've been contributing to PHP-src for about six weeks at this point. Let me apologize that this wasn't fixed sooner. I only have 24 hours in the day and I've been spending a disproportionate number of them working on the backlog of OpenSSL functionality. No one pays me to work on PHP. If at any point you feel the progress isn't up to your standards feel free to do what I did: start solving the problems and PRing fixes instead of complaining about them. Otherwise take the self-righteousness on down the road. Previous Comments: ------------------------------------------------------------------------ [2014-02-20 01:28:11] glenn at zewt dot org Ignoring bug reports for a year and a half--especially detailed, security-related reports that suggest a specific fix--is an effective way to discourage people from reporting bugs. Calling an issue like this a "feature request" doesn't help, either. ------------------------------------------------------------------------ [2014-02-20 00:09:29] rdlowrey@php.net Default cert locations are now loaded in the absence of a stream context specification or ini directive (openssl.cafile/openssl.capath) as of PHP 5.6. As this is more a feature request than an actual bug I'm closing the report. If the lack of this functionality creates a serious problem for people in 5.4 and 5.5 I can look at possibly backporting the feature once 5.6 is officially released. Alternatively, you can try to hassle me on this bug report :) ------------------------------------------------------------------------ [2012-05-16 21:29:53] glenn at zewt dot org Description: ------------ OpenSSL CA default certificates are not loaded. To make HTTPS certificate verification work, I have to hardcode the path to where CA certs are on the local system, eg: $req = new HTTP_Request2('https://url', HTTP_Request2::METHOD_GET, array ("ssl_capath" => "/usr/lib/ssl/certs")); This isn't portable, and it's very unobvious; it seems that some people "work around" this by disabling certificate verification, which is bad. I don't know if some distros patch around this problem, or if there's something else going on for this not to happen to everybody; I'm hitting it on Debian testing and with OpenSSL 1.0.1c. In php_SSL_new_from_context, if cafile and capath are both NULL, it looks like you only need to call SSL_CTX_set_default_verify_paths instead of SSL_CTX_load_verify_locations. Don't call it if either are specified, so people don't end up with certificates loaded when they explicitly want to load only specific ones. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=62050&edit=1

« previous php.bugs (#184373) next »