Bug #68879 [Opn->Ver]: IP Address fields in subjectAltNames not used
| From: | rdlowrey@php.net | Date: | Wed, 04 Mar 2015 17:31:03 +0000 |
| Subject: | Bug #68879 [Opn->Ver]: IP Address fields in subjectAltNames not used | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-191153@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68879&edit=1
ID: 68879
Updated by: rdlowrey@php.net
Reported by: fabian at ritter-vogt dot de
Summary: IP Address fields in subjectAltNames not used
-Status: Open
+Status: Verified
Type: Bug
Package: OpenSSL related
Operating System: openSUSE 13.1
PHP Version: 5.6.4
-Assigned To:
+Assigned To: rdlowrey
Block user comment: N
Private report: N
New Comment:
This is a known issue. Currently only DNS names from the subjectAltName field are checked. I'm
putting this on my @TODO list. Feel free to hassle me on this bug report if this isn't
addressed in the near future ;)
Previous Comments:
------------------------------------------------------------------------
[2015-01-21 19:40:30] fabian at ritter-vogt dot de
Description:
------------
The server at 10.2.0.1 has a certificate with CN set to the hostname and subjectAltNames set to the
hostname and also IP-Address:
X509v3 Subject Alternative Name:
DNS:hostname.fqdn, DNS:hostname, IP Address:10.2.0.1
The certificate is correct, the import into the local trusted CA store worked:
$ curl https://10.2.0.1/some/file.html
Hi!
The php script below, however, prints the following error message:
Peer certificate CN=
hostname' did not match expected CN=10.2.0.1'
It works if I replace "10.2.0.1" by "hostname" or "hostname.fqdn".
Test script:
---------------
<?php
file_get_contents("https://10.2.0.1/some/file.html");
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68879&edit=1