Bug #55618 [Ana->Csd]: CN_match case insenstive compare
| From: | rdlowrey@php.net | Date: | Wed, 14 Jan 2015 19:17:47 +0000 |
| Subject: | Bug #55618 [Ana->Csd]: CN_match case insenstive compare | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189955@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55618&edit=1
ID: 55618
Updated by: rdlowrey@php.net
Reported by: fkooman at tuxed dot net
Summary: CN_match case insenstive compare
-Status: Analyzed
+Status: Closed
Type: Bug
Package: OpenSSL related
PHP Version: trunk-SVN-2011-09-06 (SVN)
Assigned To: rdlowrey
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of rdlowrey
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e2fe8e164f14054170ba8ad1f2a66ef1ef5acdfa
Log: Fixed bug #55618 (use case-insensitive cert name matching)
Previous Comments:
------------------------------------------------------------------------
[2014-02-20 21:56:49] rdlowrey@php.net
This behavior has been corrected as of PHP 5.6 for both common name (CN) matches and the newly
supported subject alternative name (SAN) matching.
------------------------------------------------------------------------
[2011-09-06 11:06:26] fkooman at tuxed dot net
Does this locale dependency refer to strcasecmp() or strcasecmp_l()? It seems the former does
nothing with the locale?
Another approach might be to use toupper() and tolower() on both the CN_match value and the CN from
the certificate...
------------------------------------------------------------------------
[2011-09-06 10:44:49] cataphract@php.net
I wouldn't be comfortable using a locale dependent function like strcasecmp() for something as
matching names.
------------------------------------------------------------------------
[2011-09-06 09:05:54] fkooman at tuxed dot net
Description:
------------
CN_match does a case sensitive match to compare the name in the certificate with the name specified
in the context. It should be a case insensitive match.
Test script:
---------------
<?php
$uri = 'https://ib-groep.nl/';
$hostname = 'ib-groep.nl';
$context = stream_context_create(array(
'ssl' => array(
'verify_peer' => TRUE,
'allow_self_signed' => FALSE,
'cafile' => '/etc/pki/tls/certs/ca-bundle.trust.crt',
'CN_match' => $hostname
)
));
$web_content = file_get_contents($uri, FALSE, $context);
?>
Expected result:
----------------
The script should not throw any warning and fill $web_content with the data from the website.
Actual result:
--------------
PHP Warning: file_get_contents(): Peer certificate CN=
IB-Groep.nl' did not match
expected CN=ib-groep.nl' in /home/fkooman/test.php on line 20
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55618&edit=1