Bug #72088 [Asn->Nab]: file_get_contents() return empty in some urls
| From: | ab@php.net | Date: | Mon, 25 Apr 2016 14:17:22 +0000 |
| Subject: | Bug #72088 [Asn->Nab]: file_get_contents() return empty in some urls | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200771@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72088&edit=1
ID: 72088
Updated by: ab@php.net
Reported by: alejosimon at gmail dot com
Summary: file_get_contents() return empty in some urls
-Status: Assigned
+Status: Not a bug
Type: Bug
Package: HTTP related
Operating System: Windows 7 x64
PHP Version: 7.0.5
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Thanks for the check.
Not sure about the x86/x64 diff, i was able to reproduce with both. I guess it's some
environment issue on your side. You should check that it loads the correct OpenSSL, etc.
And, I'd really suggest to report this to the corresponding admins. Even Firefox blocks if I go
to https://afip.gov.ar/ . The encryption there is just insecure.
For the Windows deps, we have no other choice that to follow the security advisory.
With this, time to close.
Thanks
Previous Comments:
------------------------------------------------------------------------
[2016-04-25 13:34:41] alejosimon at gmail dot com
Hahahaaaaa, sorry for my stupidity ... now it works !!!!!! You were right! THANK YOU VERY MUCH!!!
...but why that difference between x64 and x32 ???
Now results in all versions of PHP:
Array
(
[0] => HTTP/1.1 200 OK
[1] => Connection: close
[2] => Date: Mon, 25 Apr 2016 13:30:01 GMT
[3] => Server: Microsoft-IIS/6.0
[4] => MicrosoftOfficeWebServer: 5.0_Pub
[5] => X-Powered-By: ASP.NET
[6] => X-AspNet-Version: 2.0.50727
[7] => Cache-Control: private, max-age=0
[8] => Content-Type: text/xml; charset=utf-8
[9] => Content-Length: 24646
)
THANKS 2
------------------------------------------------------------------------
[2016-04-25 13:20:45] ab@php.net
@alejosimon, thanks for staying on this. Yeah, you've used the wrong option. Here's how it
should be:
$url = 'https://wswhomo.afip.gov.ar/wsfe/service.asmx?wsdl'
;
$opts = array(
"ssl" => array(
"ciphers" => "TLSv1",
)
);
$context = stream_context_create($opts);
$response = file_get_contents($url, false, $context);
var_dump( $http_response_header );
Thanks.
------------------------------------------------------------------------
[2016-04-25 13:04:02] alejosimon at gmail dot com
@ab, Sorry, but we still have the error :( My test into TLSv1.0 context.
<?php
error_reporting(E_ALL);
ini_set("display_errors", 1);
$context = stream_context_create(
array(
'ssl' => array(
'protocol_version' => 'tls1',
),
));
$url = 'https://wswhomo.afip.gov.ar/wsfe/service.asmx?wsdl'
; // FAIL!!!
//$url = 'https://wsaahomo.afip.gov.ar/ws/services/LoginCms?wsdl'
; // OK
//$url = 'https://servicios1.afip.gov.ar/wsfe/service.asmx?wsdl'
; // OK
//$url = 'https://www.google.com.ar' ; // OK
$response = file_get_contents( $url, false, $context );
print_r( $http_response_header );
?>
Result in php 7.0.5 win64:
Array(
)
--------------------------
Result in php 5.6.20 win32:
Array
(
[0] => HTTP/1.1 200 OK
[1] => Connection: close
[2] => Date: Mon, 25 Apr 2016 12:51:29 GMT
[3] => Server: Microsoft-IIS/6.0
[4] => MicrosoftOfficeWebServer: 5.0_Pub
[5] => X-Powered-By: ASP.NET
[6] => X-AspNet-Version: 2.0.50727
[7] => Cache-Control: private, max-age=0
[8] => Content-Type: text/xml; charset=utf-8
[9] => Content-Length: 24646
)
Thanks!
------------------------------------------------------------------------
[2016-04-25 12:51:45] ab@php.net
@alejosimon, I reproduce with both x86 and x64, and it actually should be so as they have the same
OpenSSL version. We've OpenSSL 1.0.1 in 5.6 vs 1.0.2 in 7.0.
Testing with even earlier 7.0 version with OpenSSL preceding the latest security advisory, the issue
is actually the same. So more about some OpenSSL 1.0.2 behavior change.
You need to create a stream context enforcing TLSv1. IIS6 is a very old and already unsupported
software, so i'd barely see this as a bug anyway.
Thanks.
------------------------------------------------------------------------
[2016-04-25 12:39:48] alejosimon at gmail dot com
My loaded modules in PHP 7.0.5 win64...
[PHP Modules]
bcmath
bz2
calendar
com_dotnet
Core
ctype
curl
date
dom
exif
filter
ftp
gd
gettext
gmp
hash
iconv
imap
intl
json
ldap
libxml
mbstring
mcrypt
mysqli
mysqlnd
openssl
pcre
PDO
pdo_mysql
PDO_ODBC
pdo_pgsql
pdo_sqlite
pgsql
Phar
pthreads
Reflection
session
SimpleXML
soap
sockets
SPL
sqlite3
standard
tidy
tokenizer
wddx
xml
xmlreader
xmlrpc
xmlwriter
xsl
Zend OPcache
zip
zlib
[Zend Modules]
Zend OPcache
Sorry and thanks!
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72088
--
Edit this bug report at https://bugs.php.net/bug.php?id=72088&edit=1