Bug #67666 [NEW]: Subject alternative name verification does not match wildcards
| From: | thijs at debian dot org | Date: | Tue, 22 Jul 2014 11:42:28 +0000 |
| Subject: | Bug #67666 [NEW]: Subject alternative name verification does not match wildcards | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-186770@lists.php.net to get a copy of this message | ||
From: thijs at debian dot org
Operating system: Debian sid
PHP version: 5.6.0RC2
Package: OpenSSL related
Bug Type: Bug
Bug description:Subject alternative name verification does not match wildcards
Description:
------------
When fetching things from an https:// url with PHP (e.g.
file_get_contents()), the hostname is matched against the names in the
certificate's subject alternative names extension since PHP 5.6, good.
However, it does not apply the wildcard matching that it does to common
names to these names, therefore https requests to resources on a server
that has a wildcard SAN fail.
An example site that has such a certificate is
https://raw.githubusercontent.com.
The test script below reproduces the problem for me.
Test script:
---------------
<?php
ini_set("display_errors", TRUE);
$readme =
file_get_contents('https://raw.githubusercontent.com/php/php-src/master/README.md');
echo $readme;
Expected result:
----------------
Contents of README.md.
Actual result:
--------------
Warning: file_get_contents(): Peer certificate CN=`www.github.com' did
not match expected CN=`raw.githubusercontent.com' in /srv/www/test.php
on line 6
Warning: file_get_contents(): Failed to enable crypto in
/srv/www/test.php on line 6
Warning:
file_get_contents(https://raw.githubusercontent.com/php/php-src/master/README.md):
failed to open stream: operation failed in /srv/www/test.php on line 6
--
Edit bug report at https://bugs.php.net/bug.php?id=67666&edit=1
--