Bug #67666 [Com]: Subject alternative name verification does not match wildcards

From: Date: Thu, 24 Jul 2014 13:13:22 +0000
Subject: Bug #67666 [Com]: Subject alternative name verification does not match wildcards
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186798@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67666&edit=1 ID: 67666 Comment by: rdlowrey@php.net Reported by: thijs at debian dot org Summary: Subject alternative name verification does not match wildcards Status: Closed Type: Bug Package: OpenSSL related Operating System: Debian sid PHP Version: 5.6.0RC2 Block user comment: N Private report: N New Comment: Thanks Tjerk, everything looks good. For posterity here's the relevant spec coverage for the topic of wildcard matching in SAN names from RFC 6125: A "*" wildcard character MAY be used as the left-most name component in the certificate. For example, *.example.com would match a.example.com, foo.example.com, etc. but would not match example.com. Previous Comments: ------------------------------------------------------------------------ [2014-07-24 06:56:13] thijs at debian dot org Thanks for the fast response! ------------------------------------------------------------------------ [2014-07-24 06:41:24] datibbaw@php.net Automatic comment on behalf of datibbaw Revision: http://git.php.net/?p=php-src.git;a=commit;h=38e714ece52f38963c072434b12174bccedcd1c7 Log: Fixed #67666 - Subject altName doesn't match wildcards ------------------------------------------------------------------------ [2014-07-22 11:42:27] thijs at debian dot org Description: ------------ When fetching things from an https:// url with PHP (e.g. file_get_contents()), the hostname is matched against the names in the certificate's subject alternative names extension since PHP 5.6, good. However, it does not apply the wildcard matching that it does to common names to these names, therefore https requests to resources on a server that has a wildcard SAN fail. An example site that has such a certificate is https://raw.githubusercontent.com. The test script below reproduces the problem for me. Test script: --------------- <?php ini_set("display_errors", TRUE); $readme = file_get_contents('https://raw.githubusercontent.com/php/php-src/master/README.md'); echo $readme; Expected result: ---------------- Contents of README.md. Actual result: -------------- Warning: file_get_contents(): Peer certificate CN=www.github.com' did not match expected CN=raw.githubusercontent.com' in /srv/www/test.php on line 6 Warning: file_get_contents(): Failed to enable crypto in /srv/www/test.php on line 6 Warning: file_get_contents(https://raw.githubusercontent.com/php/php-src/master/README.md): failed to open stream: operation failed in /srv/www/test.php on line 6 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67666&edit=1

« previous php.bugs (#186798) next »