Req #70038 [Opn]: peer verification needs to be a global option

From: Date: Fri, 10 Jul 2015 12:09:13 +0000
Subject: Req #70038 [Opn]: peer verification needs to be a global option
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194301@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70038&edit=1

 ID:                 70038
 Updated by:         cmb@php.net
 Reported by:        spam2 at rhsoft dot net
 Summary:            peer verification needs to be a global option
 Status:             Open
 Type:               Feature/Change Request
 Package:            Streams related
 PHP Version:        5.6.10
 Block user comment: N
 Private report:     N

 New Comment:

It seems to me that there are two not necessarily related issues:

 a) the possibility to change default stream context options
    without touching application code
 
 b) the ability to disable peer certificate validation for
    extensions not regading default stream context options,
    respectively to make those extension regard the default stream
    context options
    
I suggest to address these issues with separate tickets.
    
a) might already be solvable by setting auto_prepend_file[1]
appropriately. If that is not viable, a special ini setting might
be in order, but I wouldn't make it PHP_INI_ALL for security
reasons.

[1] <http://www.php.net/manual/en/ini.core.php#ini.auto-prepend-file>


Previous Comments:
------------------------------------------------------------------------
[2015-07-10 10:22:06] spam2 at rhsoft dot net

stream_context_set_default() is PHP code, you have to touch every application

a PHP_INI_ALL option could be set by the sysadmin for specific vhosts or directories *without*
touching application code and that is an important difference if you have 3rd party applications you
are not allowed to touch

------------------------------------------------------------------------
[2015-07-10 10:18:48] spam2 at rhsoft dot net

https://bugs.php.net/bug.php?id=68344

------------------------------------------------------------------------
[2015-07-10 10:09:43] requinix@php.net

What part of this can't be solved with stream_context_set_default()?

------------------------------------------------------------------------
[2015-07-10 09:23:04] spam2 at rhsoft dot net

Description:
------------
it's nice that you can disable certificate-verification for file_get_contents
stream_context_create() and pass the context as param

BUT BECAUSE EVERY function in php supports the stream-wrappers this is completly inconsistent
(https://bugs.php.net/bug.php?id=68344) and not useable in real life applications which may run as
clone in testing environments

you hardly want to place stream_context_create() all over your codebase and HONESTLY if 3rd party
libraries are part of the game YOU CAN NOT DO that in many cases and so you NEED a GLOBAL
configuration parameter to disable the verification via per-directory, php.ini or inside the
application like if($config['debug_mode']) ini_set('peer_verification', 0);

it's unbelieveable that after the 5.4 disaster changing the default charset with no global
option and re-write and re-test some undret thousand LOC now ith 5.6 "default_charset" two
major releases that fallout was fixed while in the same major release the major mistake was repeated
with peer verification



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70038&edit=1


Thread (6 messages)

« previous php.bugs (#194301) next »