Bug #67666 [Com]: Subject alternative name verification does not match wildcards
| From: | rdlowrey@php.net | Date: | Thu, 24 Jul 2014 13:13:22 +0000 |
| Subject: | Bug #67666 [Com]: Subject alternative name verification does not match wildcards | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186798@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67666&edit=1
ID: 67666
Comment by: rdlowrey@php.net
Reported by: thijs at debian dot org
Summary: Subject alternative name verification does not match
wildcards
Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Debian sid
PHP Version: 5.6.0RC2
Block user comment: N
Private report: N
New Comment:
Thanks Tjerk, everything looks good. For posterity here's the relevant spec coverage for the
topic of wildcard matching in SAN names from RFC 6125:
A "*" wildcard character MAY be used as the left-most name
component in the certificate. For example, *.example.com would
match a.example.com, foo.example.com, etc. but would not match
example.com.
Previous Comments:
------------------------------------------------------------------------
[2014-07-24 06:56:13] thijs at debian dot org
Thanks for the fast response!
------------------------------------------------------------------------
[2014-07-24 06:41:24] datibbaw@php.net
Automatic comment on behalf of datibbaw
Revision: http://git.php.net/?p=php-src.git;a=commit;h=38e714ece52f38963c072434b12174bccedcd1c7
Log: Fixed #67666 - Subject altName doesn't match wildcards
------------------------------------------------------------------------
[2014-07-22 11:42:27] thijs at debian dot org
Description:
------------
When fetching things from an https:// url with PHP (e.g.
file_get_contents()), the hostname is matched against the names in the certificate's subject
alternative names extension since PHP 5.6, good. However, it does not apply the wildcard matching
that it does to common names to these names, therefore https requests to resources on a server that
has a wildcard SAN fail.
An example site that has such a certificate is https://raw.githubusercontent.com.
The test script below reproduces the problem for me.
Test script:
---------------
<?php
ini_set("display_errors", TRUE);
$readme = file_get_contents('https://raw.githubusercontent.com/php/php-src/master/README.md');
echo $readme;
Expected result:
----------------
Contents of README.md.
Actual result:
--------------
Warning: file_get_contents(): Peer certificate CN=
www.github.com' did not match expected
CN=raw.githubusercontent.com' in /srv/www/test.php on line 6
Warning: file_get_contents(): Failed to enable crypto in /srv/www/test.php on line 6
Warning: file_get_contents(https://raw.githubusercontent.com/php/php-src/master/README.md): failed
to open stream: operation failed in /srv/www/test.php on line 6
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67666&edit=1