Req #70038 [Opn]: peer verification needs to be a global option

From: Date: Fri, 10 Jul 2015 12:15:03 +0000
Subject: Req #70038 [Opn]: peer verification needs to be a global option
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194302@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70038&edit=1 ID: 70038 User updated by: spam2 at rhsoft dot net Reported by: spam2 at rhsoft dot net Summary: peer verification needs to be a global option Status: Open Type: Feature/Change Request Package: Streams related PHP Version: 5.6.10 Block user comment: N Private report: N New Comment: "auto_prepend_file" is a really dirty workaround > but I wouldn't make it PHP_INI_ALL for security reasons which security reasons? if stream_context_set_default() would be respected as it should be you could change it already in the script and there is no point to not have that option for php.ini, httpd.conf and <VirtualHost> as well as <Directory> Previous Comments: ------------------------------------------------------------------------ [2015-07-10 12:09:12] cmb@php.net It seems to me that there are two not necessarily related issues: a) the possibility to change default stream context options without touching application code b) the ability to disable peer certificate validation for extensions not regading default stream context options, respectively to make those extension regard the default stream context options I suggest to address these issues with separate tickets. a) might already be solvable by setting auto_prepend_file[1] appropriately. If that is not viable, a special ini setting might be in order, but I wouldn't make it PHP_INI_ALL for security reasons. [1] <http://www.php.net/manual/en/ini.core.php#ini.auto-prepend-file> ------------------------------------------------------------------------ [2015-07-10 10:22:06] spam2 at rhsoft dot net stream_context_set_default() is PHP code, you have to touch every application a PHP_INI_ALL option could be set by the sysadmin for specific vhosts or directories *without* touching application code and that is an important difference if you have 3rd party applications you are not allowed to touch ------------------------------------------------------------------------ [2015-07-10 10:18:48] spam2 at rhsoft dot net https://bugs.php.net/bug.php?id=68344 ------------------------------------------------------------------------ [2015-07-10 10:09:43] requinix@php.net What part of this can't be solved with stream_context_set_default()? ------------------------------------------------------------------------ [2015-07-10 09:23:04] spam2 at rhsoft dot net Description: ------------ it's nice that you can disable certificate-verification for file_get_contents stream_context_create() and pass the context as param BUT BECAUSE EVERY function in php supports the stream-wrappers this is completly inconsistent (https://bugs.php.net/bug.php?id=68344) and not useable in real life applications which may run as clone in testing environments you hardly want to place stream_context_create() all over your codebase and HONESTLY if 3rd party libraries are part of the game YOU CAN NOT DO that in many cases and so you NEED a GLOBAL configuration parameter to disable the verification via per-directory, php.ini or inside the application like if($config['debug_mode']) ini_set('peer_verification', 0); it's unbelieveable that after the 5.4 disaster changing the default charset with no global option and re-write and re-test some undret thousand LOC now ith 5.6 "default_charset" two major releases that fallout was fixed while in the same major release the major mistake was repeated with peer verification ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70038&edit=1

« previous php.bugs (#194302) next »