Bug #74636 [NEW]: negotiate auth broken for virtual hosts because of hostname canonicalization

From: Date: Tue, 23 May 2017 09:09:09 +0000
Subject: Bug #74636 [NEW]: negotiate auth broken for virtual hosts because of hostname canonicalization
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209233@lists.php.net to get a copy of this message
From: chanlists at googlemail dot com Operating system: debian 8 PHP version: 5.6.30 Package: *General Issues Bug Type: Bug Bug description:negotiate auth broken for virtual hosts because of hostname canonicalization Description: ------------ Suppose we are using a virtual host in apache where the name of the virtual host name <vhost> is a cname for the actual hostname <hostname>. In this case, the web browser will present a service ticket for HTTP/<vhost>, but the krb5 package will set the service principal to HTTP/<hostname> because of the use of gethostbyname() in the KRB5NegotiateAuth constructor. This will not work. If I modify the constructor as follows, it works: server_name = zend_compat_hash_find(HASH_OF(server), "SERVER_NAME", sizeof("SERVER_NAME")); if ( server_name != NULL ) { char *hostname = Z_STRVAL_P(server_name); // struct hostent* host = gethostbyname(hostname); // if(!host) { // zend_throw_exception(NULL, "Failed to get server FQDN - Lookup failure", 0 TSRMLS_CC); // return; //} nametmp.length = strlen(hostname) + 6; nametmp.value = emalloc(sizeof(char)*nametmp.length); snprintf(nametmp.value, nametmp.length, "HTTP@%s",hostname); Note that for this to work, one also has to set dns_canonicalize_hostname = false in /etc/krb5.conf because otherwise the krb5 library will try to do hostname canonicalization as well. So I think there should either be a way to set the name of the service principal using a method, or hostname canonicalization should be disabled in the krb5 library as above, or it should be possible to turn it off with a flag. I would be happy to contribute a patch depending on what you prefer. Thanks for this great piece of software, Christian Test script: --------------- see above -- Edit bug report at https://bugs.php.net/bug.php?id=74636&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74636&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74636&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74636&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=74636&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=74636&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=74636&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=74636&r=needscript Try newer version: https://bugs.php.net/fix.php?id=74636&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=74636&r=support Expected behavior: https://bugs.php.net/fix.php?id=74636&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=74636&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=74636&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=74636&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74636&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=74636&r=dst IIS Stability: https://bugs.php.net/fix.php?id=74636&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=74636&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=74636&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=74636&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=74636&r=mysqlcfg

« previous php.bugs (#209233) next »