Req #70038 [Opn]: peer verification needs to be a global option
| From: | spam2 at rhsoft dot net | Date: | Fri, 10 Jul 2015 12:15:03 +0000 |
| Subject: | Req #70038 [Opn]: peer verification needs to be a global option | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194302@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70038&edit=1
ID: 70038
User updated by: spam2 at rhsoft dot net
Reported by: spam2 at rhsoft dot net
Summary: peer verification needs to be a global option
Status: Open
Type: Feature/Change Request
Package: Streams related
PHP Version: 5.6.10
Block user comment: N
Private report: N
New Comment:
"auto_prepend_file" is a really dirty workaround
> but I wouldn't make it PHP_INI_ALL for security reasons
which security reasons?
if stream_context_set_default() would be respected as it should be you could change it already in
the script and there is no point to not have that option for php.ini, httpd.conf and
<VirtualHost> as well as <Directory>
Previous Comments:
------------------------------------------------------------------------
[2015-07-10 12:09:12] cmb@php.net
It seems to me that there are two not necessarily related issues:
a) the possibility to change default stream context options
without touching application code
b) the ability to disable peer certificate validation for
extensions not regading default stream context options,
respectively to make those extension regard the default stream
context options
I suggest to address these issues with separate tickets.
a) might already be solvable by setting auto_prepend_file[1]
appropriately. If that is not viable, a special ini setting might
be in order, but I wouldn't make it PHP_INI_ALL for security
reasons.
[1] <http://www.php.net/manual/en/ini.core.php#ini.auto-prepend-file>
------------------------------------------------------------------------
[2015-07-10 10:22:06] spam2 at rhsoft dot net
stream_context_set_default() is PHP code, you have to touch every application
a PHP_INI_ALL option could be set by the sysadmin for specific vhosts or directories *without*
touching application code and that is an important difference if you have 3rd party applications you
are not allowed to touch
------------------------------------------------------------------------
[2015-07-10 10:18:48] spam2 at rhsoft dot net
https://bugs.php.net/bug.php?id=68344
------------------------------------------------------------------------
[2015-07-10 10:09:43] requinix@php.net
What part of this can't be solved with stream_context_set_default()?
------------------------------------------------------------------------
[2015-07-10 09:23:04] spam2 at rhsoft dot net
Description:
------------
it's nice that you can disable certificate-verification for file_get_contents
stream_context_create() and pass the context as param
BUT BECAUSE EVERY function in php supports the stream-wrappers this is completly inconsistent
(https://bugs.php.net/bug.php?id=68344) and not useable in real life applications which may run as
clone in testing environments
you hardly want to place stream_context_create() all over your codebase and HONESTLY if 3rd party
libraries are part of the game YOU CAN NOT DO that in many cases and so you NEED a GLOBAL
configuration parameter to disable the verification via per-directory, php.ini or inside the
application like if($config['debug_mode']) ini_set('peer_verification', 0);
it's unbelieveable that after the 5.4 disaster changing the default charset with no global
option and re-write and re-test some undret thousand LOC now ith 5.6 "default_charset" two
major releases that fallout was fixed while in the same major release the major mistake was repeated
with peer verification
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70038&edit=1