Bug #68879 [Csd]: IP Address fields in subjectAltNames not used

From: Date: Thu, 05 Mar 2015 05:49:12 +0000
Subject: Bug #68879 [Csd]: IP Address fields in subjectAltNames not used
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191174@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68879&edit=1 ID: 68879 Updated by: rdlowrey@php.net Reported by: fabian at ritter-vogt dot de Summary: IP Address fields in subjectAltNames not used Status: Closed Type: Bug Package: OpenSSL related Operating System: openSUSE 13.1 PHP Version: 5.6.4 Assigned To: rdlowrey Block user comment: N Private report: N New Comment: This has been fixed upstream with the following commit: http://git.php.net/?p=php-src.git;a=commit;h=5dcace058a1384c8475e144e11310e260235dc3c Only IPv4 SAN matching has been implemented. I didn't bother with IPv6 matching specifically because IP SAN names have been deprecated and CAs are no longer allowed to issue them after 2015. Any certs relying on IP SAN names must migrate away from them sooner rather than later. Thanks for the report :) Previous Comments: ------------------------------------------------------------------------ [2015-03-05 05:45:00] rdlowrey@php.net Automatic comment on behalf of rdlowrey Revision: http://git.php.net/?p=php-src.git;a=commit;h=5dcace058a1384c8475e144e11310e260235dc3c Log: Fixed bug #68879 (IP Address fields in subjectAltNames not used) ------------------------------------------------------------------------ [2015-03-05 05:44:45] rdlowrey@php.net Automatic comment on behalf of rdlowrey Revision: http://git.php.net/?p=php-src.git;a=commit;h=5dcace058a1384c8475e144e11310e260235dc3c Log: Fixed bug #68879 (IP Address fields in subjectAltNames not used) ------------------------------------------------------------------------ [2015-03-04 17:31:02] rdlowrey@php.net This is a known issue. Currently only DNS names from the subjectAltName field are checked. I'm putting this on my @TODO list. Feel free to hassle me on this bug report if this isn't addressed in the near future ;) ------------------------------------------------------------------------ [2015-01-21 19:40:30] fabian at ritter-vogt dot de Description: ------------ The server at 10.2.0.1 has a certificate with CN set to the hostname and subjectAltNames set to the hostname and also IP-Address: X509v3 Subject Alternative Name: DNS:hostname.fqdn, DNS:hostname, IP Address:10.2.0.1 The certificate is correct, the import into the local trusted CA store worked: $ curl https://10.2.0.1/some/file.html Hi! The php script below, however, prints the following error message: Peer certificate CN=hostname' did not match expected CN=10.2.0.1' It works if I replace "10.2.0.1" by "hostname" or "hostname.fqdn". Test script: --------------- <?php file_get_contents("https://10.2.0.1/some/file.html"); ?> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68879&edit=1

« previous php.bugs (#191174) next »