Bug #69345 [NEW]: tls:// wrapper disables TLS 1.1+

From: Date: Wed, 01 Apr 2015 10:39:20 +0000
Subject: Bug #69345 [NEW]: tls:// wrapper disables TLS 1.1+
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191763@lists.php.net to get a copy of this message
From: cf0hay at gmail dot com Operating system: Linux 64bit PHP version: 5.6.7 Package: Sockets related Bug Type: Bug Bug description:tls:// wrapper disables TLS 1.1+ Description: ------------ When creating a socket through tls:// wrapper, any TLS version over TLS 1.0 is disabled, even with the library supports higher versions. Only TLS 1.0 accepted. With ssl:// this problem does not occur. tls:// should enable everything over TLS 1.0 too. At the present moment it's impossible to to create a socket with TLS 1.2 support but without SSL 3 (because of POODLE). Test script: --------------- <?php stream_socket_accept( stream_socket_server( "tls://127.0.0.1:4433", $errno, $errstr, STREAM_SERVER_BIND | STREAM_SERVER_LISTEN, stream_context_create([ "ssl" => [ "ciphers" => "AECDH-AES256-SHA", ], ]) ) ); Expected result: ---------------- start the test script in one console, and issue this in another: $ openssl s_client -tls1_2 -cipher AECDH-AES256-SHA [...] Cipher : AECDH-AES256-SHA [...] The PHP script should end silently. Actual result: -------------- start the test script in one console, and issue this in another: $ openssl s_client -tls1_2 -cipher AECDH-AES256-SHA [...] [...]error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number[...] [...] The PHP script throws warnings before exiting: PHP Warning: stream_socket_accept(): SSL operation failed with code 1. OpenSSL Error messages: error:1409442E:SSL routines:SSL3_READ_BYTES:tlsv1 alert protocol version PHP Warning: stream_socket_accept(): Failed to enable crypto PHP Warning: stream_socket_accept(): accept failed: Success -- Edit bug report at https://bugs.php.net/bug.php?id=69345&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69345&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69345&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69345&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=69345&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=69345&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=69345&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=69345&r=needscript Try newer version: https://bugs.php.net/fix.php?id=69345&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=69345&r=support Expected behavior: https://bugs.php.net/fix.php?id=69345&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=69345&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=69345&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=69345&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69345&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=69345&r=dst IIS Stability: https://bugs.php.net/fix.php?id=69345&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=69345&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=69345&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=69345&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=69345&r=mysqlcfg

« previous php.bugs (#191763) next »