Bug #67666 [NEW]: Subject alternative name verification does not match wildcards

From: Date: Tue, 22 Jul 2014 11:42:28 +0000
Subject: Bug #67666 [NEW]: Subject alternative name verification does not match wildcards
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186770@lists.php.net to get a copy of this message
From: thijs at debian dot org Operating system: Debian sid PHP version: 5.6.0RC2 Package: OpenSSL related Bug Type: Bug Bug description:Subject alternative name verification does not match wildcards Description: ------------ When fetching things from an https:// url with PHP (e.g. file_get_contents()), the hostname is matched against the names in the certificate's subject alternative names extension since PHP 5.6, good. However, it does not apply the wildcard matching that it does to common names to these names, therefore https requests to resources on a server that has a wildcard SAN fail. An example site that has such a certificate is https://raw.githubusercontent.com. The test script below reproduces the problem for me. Test script: --------------- <?php ini_set("display_errors", TRUE); $readme = file_get_contents('https://raw.githubusercontent.com/php/php-src/master/README.md'); echo $readme; Expected result: ---------------- Contents of README.md. Actual result: -------------- Warning: file_get_contents(): Peer certificate CN=`www.github.com' did not match expected CN=`raw.githubusercontent.com' in /srv/www/test.php on line 6 Warning: file_get_contents(): Failed to enable crypto in /srv/www/test.php on line 6 Warning: file_get_contents(https://raw.githubusercontent.com/php/php-src/master/README.md): failed to open stream: operation failed in /srv/www/test.php on line 6 -- Edit bug report at https://bugs.php.net/bug.php?id=67666&edit=1 --

« previous php.bugs (#186770) next »