Bug #69137 [Com]: Peer verification fails when using a proxy with SoapClient

From: Date: Wed, 21 Sep 2016 08:36:18 +0000
Subject: Bug #69137 [Com]: Peer verification fails when using a proxy with SoapClient
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204163@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69137&edit=1 ID: 69137 Comment by: tom at netz98 dot de Reported by: nj506 at zepler dot net Summary: Peer verification fails when using a proxy with SoapClient Status: Open Type: Bug Package: SOAP related Operating System: All PHP Version: 5.6.6 Block user comment: N Private report: N New Comment: I can confirm this problem. You need a SSL connection via a proxy to reproduce it. The exact error can be made visible by using your own error-handler before sending the SOAP request, e.g. set_error_handler( function ($errno , $errstr, $errfile = null, $errline = null) { printf( "ERROR #%d: %s in %s line %s\n", $errno, $errstr, $errfile, $errline ); } ); This produces an error like: > ERROR #2: SoapClient::__doRequest(): Peer certificate CN=)�'ï > ¯V¡cºñÈKmߦcorrect-domain.exmaple.com' did not match expected CN=5j > “ÇÜÜ�ÃõH@ÚŠproxy.example.net' The SOAP Fault itself is little saying as reported: > Fatal error: Uncaught SoapFault exception: [HTTP] Could not connect to host Previous Comments: ------------------------------------------------------------------------ [2015-06-10 12:49:26] nj506 at zepler dot net I just wanted to add the following, as it may help people track down this issue: An E_WARNING is triggered in this case, though the error_reporting value is set to exclude E_WARNING level errors (amongst others) here - https://github.com/php/php-src/blob/942809909e1bc125db038796c0a1a0b53eeaca7d/ext/soap/php_http.c#L189 It is possible to observe the error with a customer error handler registered, however - this resolves to something like: "SoapClient::__doRequest(): Peer certificate CN=example.com' did not match expected CN=192.168.1.155'" If you see this, and have a proxy set, then you probably are being affected by this bug. ------------------------------------------------------------------------ [2015-02-27 11:12:04] nj506 at zepler dot net Description: ------------ This is the same issue as presented in #67609 - but manifested in the SOAP extension. The SOAP extension uses it's own HTTP handling code (i.e. not http_fopen_wrapper.c where the issue was patched for #67609). (i) The crypto method defaults to SSL v2/3 - https://github.com/php/php-src/blob/942809909e1bc125db038796c0a1a0b53eeaca7d/ext/soap/php_http.c#L273 - this causes problems when the SOAP endpoint only accepts TLS. This can be worked around by setting 'ssl_method' to SOAP_SSL_METHOD_TLS in the options supplied to \SoapClient::__construct(). (ii) The name in the peer certificate, by default, is compared to the "url_name" of the SSL socket - https://github.com/php/php-src/blob/c17e007a293356a5b1e511626addb9f13d4eaaee/ext/openssl/xp_ssl.c#L489 - when a proxy is in use, this is the proxy host, not SOAP endpoint host. This can be worked around by setting "verify_peer_name" to FALSE, or specifying the correct "peer_name" value in the SSL portion of stream context that can be supplied within in the "stream_context" option for \SoapClient::__construct(). By the way, the error raised by SOAP where peer verification fails is very generic, to the point that it is basically impossible to work out what exactly the problem is. I couldn't see anything in the Exception context that indicated the exact problem. Test script: --------------- $options = [ 'proxy_host' => '..', 'proxy_port' => .. ]; $client = new \SoapClient($wsdl, $options); $client->__soapCall(..); Expected result: ---------------- Call succeeds Actual result: -------------- \SoapFault: Could not connect to host ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69137&edit=1

« previous php.bugs (#204163) next »