Bug #67609 [Opn->Asn]: TLS encryption fails behind HTTP proxy

From: Date: Sat, 12 Jul 2014 04:18:20 +0000
Subject: Bug #67609 [Opn->Asn]: TLS encryption fails behind HTTP proxy
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186575@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67609&edit=1 ID: 67609 Updated by: rdlowrey@php.net Reported by: rdlowrey@php.net Summary: TLS encryption fails behind HTTP proxy -Status: Open +Status: Assigned Type: Bug Package: OpenSSL related Operating System: centos PHP Version: 5.6.0RC2 -Assigned To: +Assigned To: rdlowrey Block user comment: N Private report: N New Comment: The problem here is two-fold: (1) The existing ssl proxying code still uses the STREAM_CRYPTO_METHOD_SSLv23_CLIENT constant. In previous versions this constant meant "any available SSL/TLS protocol." However in 5.6 this constant now represents "only SSLv2 or SSLv3." Many servers disallow SSLv2/3 altogether as they are both known to be insecure. This results in failures for many servers. Fixing this issue requires a simple change to use the new (as of 5.6) STREAM_CRYPTO_METHOD_ANY_CLIENT crypto method constant. (2) As of 5.6 ext/openssl automatically detects the host name from the HTTP request URI if no peer name is specified as part of the SSL stream context. For connections routed through a proxy, though, the proxy server's host name is detected and this results in handshake failures because the proxy name doesn't match the name on the remote server's certificate. The fix here is a matter of setting the appropriate server hostname if no peer_name is set in the SSL context to avoid auto-detection of the proxy server's name. I've already fixed these issues locally. I'll commit the changes and update this report once I'm able to do due diligence and ensure I haven't missed any edge cases. Previous Comments: ------------------------------------------------------------------------ [2014-07-12 04:07:25] rdlowrey@php.net Description: ------------ Connection to encrypted resources from behind an HTTP proxy using 5.6.0RC2 always fails. The failure is unaffected by manually assigning the appropriate SSL stream context options. This bug only manifests when connecting via SSL/TLS through a proxy server and other use-cases are unaffected. Test script: --------------- <?php // Must have exported proxy environment vars, e.g.: // export http_proxy=http://127.0.0.1:8888 // export https_proxy=$http_proxy // fails :( $html = file_get_contents('https://google.com'); var_dump(strlen($html)); Expected result: ---------------- int(%d) Actual result: -------------- SSL operation failed with code 1. OpenSSL Error messages: error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67609&edit=1

« previous php.bugs (#186575) next »