Bug #68879 [Csd]: IP Address fields in subjectAltNames not used
| From: | rdlowrey@php.net | Date: | Thu, 05 Mar 2015 05:49:12 +0000 |
| Subject: | Bug #68879 [Csd]: IP Address fields in subjectAltNames not used | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-191174@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68879&edit=1
ID: 68879
Updated by: rdlowrey@php.net
Reported by: fabian at ritter-vogt dot de
Summary: IP Address fields in subjectAltNames not used
Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: openSUSE 13.1
PHP Version: 5.6.4
Assigned To: rdlowrey
Block user comment: N
Private report: N
New Comment:
This has been fixed upstream with the following commit:
http://git.php.net/?p=php-src.git;a=commit;h=5dcace058a1384c8475e144e11310e260235dc3c
Only IPv4 SAN matching has been implemented. I didn't bother with IPv6 matching specifically
because IP SAN names have been deprecated and CAs are no longer allowed to issue them after 2015.
Any certs relying on IP SAN names must migrate away from them sooner rather than later.
Thanks for the report :)
Previous Comments:
------------------------------------------------------------------------
[2015-03-05 05:45:00] rdlowrey@php.net
Automatic comment on behalf of rdlowrey
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5dcace058a1384c8475e144e11310e260235dc3c
Log: Fixed bug #68879 (IP Address fields in subjectAltNames not used)
------------------------------------------------------------------------
[2015-03-05 05:44:45] rdlowrey@php.net
Automatic comment on behalf of rdlowrey
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5dcace058a1384c8475e144e11310e260235dc3c
Log: Fixed bug #68879 (IP Address fields in subjectAltNames not used)
------------------------------------------------------------------------
[2015-03-04 17:31:02] rdlowrey@php.net
This is a known issue. Currently only DNS names from the subjectAltName field are checked. I'm
putting this on my @TODO list. Feel free to hassle me on this bug report if this isn't
addressed in the near future ;)
------------------------------------------------------------------------
[2015-01-21 19:40:30] fabian at ritter-vogt dot de
Description:
------------
The server at 10.2.0.1 has a certificate with CN set to the hostname and subjectAltNames set to the
hostname and also IP-Address:
X509v3 Subject Alternative Name:
DNS:hostname.fqdn, DNS:hostname, IP Address:10.2.0.1
The certificate is correct, the import into the local trusted CA store worked:
$ curl https://10.2.0.1/some/file.html
Hi!
The php script below, however, prints the following error message:
Peer certificate CN=
hostname' did not match expected CN=10.2.0.1'
It works if I replace "10.2.0.1" by "hostname" or "hostname.fqdn".
Test script:
---------------
<?php
file_get_contents("https://10.2.0.1/some/file.html");
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68879&edit=1