Bug #69137 [Com]: Peer verification fails when using a proxy with SoapClient

From: Date: Wed, 10 Jun 2015 12:49:27 +0000
Subject: Bug #69137 [Com]: Peer verification fails when using a proxy with SoapClient
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193303@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69137&edit=1

 ID:                 69137
 Comment by:         nj506 at zepler dot net
 Reported by:        nj506 at zepler dot net
 Summary:            Peer verification fails when using a proxy with
                     SoapClient
 Status:             Open
 Type:               Bug
 Package:            SOAP related
 Operating System:   All
 PHP Version:        5.6.6
 Block user comment: N
 Private report:     N

 New Comment:

I just wanted to add the following, as it may help people track down this issue:

An E_WARNING is triggered in this case, though the error_reporting value is set to exclude E_WARNING
level errors (amongst others) here - https://github.com/php/php-src/blob/942809909e1bc125db038796c0a1a0b53eeaca7d/ext/soap/php_http.c#L189

It is possible to observe the error with a customer error handler registered, however -  this
resolves to something like:

"SoapClient::__doRequest(): Peer certificate CN=example.com' did not match expected
CN=192.168.1.155'"

If you see this, and have a proxy set, then you probably are being affected by this bug.


Previous Comments:
------------------------------------------------------------------------
[2015-02-27 11:12:04] nj506 at zepler dot net

Description:
------------
This is the same issue as presented in #67609 - but manifested in the SOAP extension. The SOAP
extension uses it's own HTTP handling code (i.e. not http_fopen_wrapper.c where the issue was
patched for #67609).

(i) The crypto method defaults to SSL v2/3 - https://github.com/php/php-src/blob/942809909e1bc125db038796c0a1a0b53eeaca7d/ext/soap/php_http.c#L273
- this causes problems when the SOAP endpoint only accepts TLS.

This can be worked around by setting 'ssl_method' to SOAP_SSL_METHOD_TLS in the options
supplied to \SoapClient::__construct().

(ii) The name in the peer certificate, by default, is compared to the "url_name" of the
SSL socket - https://github.com/php/php-src/blob/c17e007a293356a5b1e511626addb9f13d4eaaee/ext/openssl/xp_ssl.c#L489
- when a proxy is in use, this is the proxy host, not SOAP endpoint host.

This can be worked around by setting "verify_peer_name" to FALSE, or specifying the
correct "peer_name" value in the SSL portion of stream context that can be supplied within
in the "stream_context" option for \SoapClient::__construct().

By the way, the error raised by SOAP where peer verification fails is very generic, to the point
that it is basically impossible to work out what exactly the problem is. I couldn't see
anything in the Exception context that indicated the exact problem.

Test script:
---------------
$options = [
  'proxy_host' => '..',
  'proxy_port' => ..
];

$client = new \SoapClient($wsdl, $options);
$client->__soapCall(..);

Expected result:
----------------
Call succeeds

Actual result:
--------------
\SoapFault: Could not connect to host


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69137&edit=1


Thread (7 messages)

« previous php.bugs (#193303) next »