Bug #69137 [NEW]: Peer verification fails when using a proxy with SoapClient
| From: | nj506 at zepler dot net | Date: | Fri, 27 Feb 2015 11:12:05 +0000 |
| Subject: | Bug #69137 [NEW]: Peer verification fails when using a proxy with SoapClient | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-190988@lists.php.net to get a copy of this message | ||
From: nj506 at zepler dot net
Operating system: All
PHP version: 5.6.6
Package: SOAP related
Bug Type: Bug
Bug description:Peer verification fails when using a proxy with SoapClient
Description:
------------
This is the same issue as presented in #67609 - but manifested in the
SOAP extension. The SOAP extension uses it's own HTTP handling code
(i.e. not http_fopen_wrapper.c where the issue was patched for #67609).
(i) The crypto method defaults to SSL v2/3 -
https://github.com/php/php-src/blob/942809909e1bc125db038796c0a1a0b53eeaca7d/ext/soap/php_http.c#L273
- this causes problems when the SOAP endpoint only accepts TLS.
This can be worked around by setting 'ssl_method' to SOAP_SSL_METHOD_TLS
in the options supplied to \SoapClient::__construct().
(ii) The name in the peer certificate, by default, is compared to the
"url_name" of the SSL socket -
https://github.com/php/php-src/blob/c17e007a293356a5b1e511626addb9f13d4eaaee/ext/openssl/xp_ssl.c#L489
- when a proxy is in use, this is the proxy host, not SOAP endpoint
host.
This can be worked around by setting "verify_peer_name" to FALSE, or
specifying the correct "peer_name" value in the SSL portion of stream
context that can be supplied within in the "stream_context" option for
\SoapClient::__construct().
By the way, the error raised by SOAP where peer verification fails is
very generic, to the point that it is basically impossible to work out
what exactly the problem is. I couldn't see anything in the Exception
context that indicated the exact problem.
Test script:
---------------
$options = [
'proxy_host' => '..',
'proxy_port' => ..
];
$client = new \SoapClient($wsdl, $options);
$client->__soapCall(..);
Expected result:
----------------
Call succeeds
Actual result:
--------------
\SoapFault: Could not connect to host
--
Edit bug report at https://bugs.php.net/bug.php?id=69137&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69137&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69137&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69137&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69137&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69137&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69137&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69137&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69137&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69137&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69137&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69137&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69137&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69137&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69137&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69137&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69137&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69137&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69137&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69137&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69137&r=mysqlcfg