Bug #73388 [Asn]: STREAM_CRYPTO_METHOD_TLS_CLIENT restricted to TLS1.0 only
| From: | arjen at parse dot nl | Date: | Wed, 02 Nov 2016 11:53:29 +0000 |
| Subject: | Bug #73388 [Asn]: STREAM_CRYPTO_METHOD_TLS_CLIENT restricted to TLS1.0 only | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205143@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73388&edit=1
ID: 73388
User updated by: arjen at parse dot nl
Reported by: arjen at parse dot nl
Summary: STREAM_CRYPTO_METHOD_TLS_CLIENT restricted to TLS1.0
only
Status: Assigned
Type: Bug
Package: OpenSSL related
Operating System: Linux
PHP Version: 7.0.12
Assigned To: rdlowrey
Block user comment: N
Private report: N
New Comment:
I don't think introducing more constants makes it safer..
If STREAM_CRYPTO_METHOD_MINIMUM_TLSv1_0_CLIENT is created and TLSv1_0 is considered insecure, what
would happen to the constant? Modified to NOT include v1_0? Dropped?
If we define STREAM_CRYPTO_METHOD_TLS_CLIENT as the 'recommended/safe set of TLS
versions', new TLS versions (1.3) can be added and once TLS 1.0 is considered insecure it can
be removed. Like what has been done to STREAM_CRYPTO_METHOD_SSLv23_CLIENT, but without the confusing
name.
If a developer wants to explicitly choose which versions to support, he should create his own
constant with a combination of
STREAM_CRYPTO_METHOD_TLSv1_0_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_1_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_2_CLIENT
Changes to the STREAM_CRYPTO_METHOD_TLS_CLIENT constant should be mentioned in the CHANGES file, so
developers could choose to pick their own set of versions.
Previous Comments:
------------------------------------------------------------------------
[2016-11-02 08:35:22] bwoebi@php.net
I fundamentally agree here.
We cannot change STREAM_CRYPTO_METHOD_SSLv23_CLIENT due to it meaning worse support, but I suppose
we're safe changing STREAM_CRYPTO_METHOD_TLS_CLIENT (and the _SERVER counterpart) to any TLS
version.
At that point adding STREAM_CRYPTO_METHOD_TLS_ANY_CLIENT is useless.
What I would recommend however, is a constant for each TLS version supporting that version *and all
higher versions*.
I.e.
STREAM_CRYPTO_METHOD_MINIMUM_TLSv1_0_CLIENT =
STREAM_CRYPTO_METHOD_TLSv1_0_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_1_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_2_CLIENT
STREAM_CRYPTO_METHOD_MINIMUM_TLSv1_1_CLIENT =
STREAM_CRYPTO_METHOD_TLSv1_1_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_2_CLIENT
STREAM_CRYPTO_METHOD_MINIMUM_TLSv1_2_CLIENT = STREAM_CRYPTO_METHOD_TLSv1_2_CLIENT
And when TLSv1.3 gets added, it automatically is added to these constants. Which is what you
typically want, I think.
------------------------------------------------------------------------
[2016-10-26 09:42:57] arjen at parse dot nl
STREAM_CRYPTO_METHOD_TLS_ANY_CLIENT should be exposed and should match all future TLS version (like
1.3).
AND the existing STREAM_CRYPTO_METHOD_TLS_CLIENT should be updated to include
STREAM_CRYPTO_METHOD_TLSv1_1_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_2_CLIENT (and possibly no future TLS
versions). Just like STREAM_CRYPTO_METHOD_SSLv23_CLIENT got it added in 5.6.7.
Why add it to the STREAM_CRYPTO_METHOD_SSLv23_CLIENT constant and not
STREAM_CRYPTO_METHOD_TLS_CLIENT? It makes no sense. People upgrading their code from SSLv23_CLIENT
(sounds pretty old) to TLS_CLIENT get worse protocol support.
STREAM_CRYPTO_METHOD_TLS_CLIENT
PHP TLS 1.0 TLS 1.1 TLS 1.2 SSL23
5.5.x: + no supported not supported -
5.6.0-5.6.6 + + + -
5.6.7- + - - -
STREAM_CRYPTO_METHOD_SSLv23_CLIENT
PHP TLS 1.0 TLS 1.1 TLS 1.2 SSL23
5.5.x: + no supported not supported +
5.6.0-5.6.6 - - - +
5.6.7- + + + -
------------------------------------------------------------------------
[2016-10-26 09:11:24] kalle@php.net
It seems reasonable to expose this constant, assigning it to you Daniel as you did the bug fix
commit back then :)
------------------------------------------------------------------------
[2016-10-26 07:56:40] arjen at parse dot nl
And the STREAM_CRYPTO_METHOD_TLS_ANY_CLIENT constant created in https://github.com/php/php-src/commit/10bc5fd4c4c8e1dd57bd911b086e9872a56300a0
should be exposed as constant in userland in https://github.com/php/php-src/blob/6053987bc27e8dede37f437193a5cad448f99bce/ext/standard/file.c#L223
------------------------------------------------------------------------
[2016-10-26 07:48:29] arjen at parse dot nl
Description:
------------
In 5.6 some openssl improvements were made: http://php.net/manual/en/migration56.openssl.php
The changelog mentions STREAM_CRYPTO_METHOD_TLS_CLIENT as constant for any TLS version.
Because of BC, this was reverted in https://bugs.php.net/bug.php?id=69195
STREAM_CRYPTO_METHOD_TLS_CLIENT is now TLSv1.0 only, while STREAM_CRYPTO_METHOD_SSLv23_CLIENT =
STREAM_CRYPTO_METHOD_TLSv1_0_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_1_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_2_CLIENT
(see http://php.net/manual/en/function.stream-socket-enable-crypto.php#119122)
We started using the STREAM_CRYPTO_METHOD_TLS_CLIENT constant with 5.6.0 and now found out we
couldn't connect to a service only supporting TLS v1.1 and v1.2 So by following the changelog
and using a TLS_CLIENT specific constant, we ended up in a situation with WORSE TLS version
support...
A quick search on github on STREAM_CRYPTO_METHOD_TLS_CLIENT language:PHP returns 207,607
occurrences, while STREAM_CRYPTO_METHOD_SSLv23_CLIENT returns 28,956 results.
Solution: STREAM_CRYPTO_METHOD_TLS_CLIENT should also enable
STREAM_CRYPTO_METHOD_TLSv1_1_CLIENT|STREAM_CRYPTO_METHOD_TLSv1_2_CLIENT
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73388&edit=1