From: root dot talis at gmail dot com
Operating system: Elementary OS 0.4.1 Loki
PHP version: 7.1.8
Package: OpenSSL related
Bug Type: Bug
Bug description:steam_socket_enable_crypto ignores verify_peer, verify_peer_name and allow_self
Description:
------------
I try to call stream_socket_enable_crypto() on an open connection with a
self-signed certificate.
verify_peer is disabled, verify_peer_name is disabled, allow_self_signed
is enabled,
but PHP throws the following warning:
"stream_socket_enable_crypto(): Unable to set local cert chain file
`/tmp/admin.crt';
Check that your cafile/capath settings include details of your
certificate and its issuer"
PHP is installed from this repository:
https://launchpad.net/~ondrej/+archive/ubuntu/php
Unfortunately, I haven't found any information about the compile
configure line.
I believe that the PPA maintainer can provide this information.
My setup:
PHP version: PHP 7.1.8-2+ubuntu16.04.1+deb.sury.org+4 (cli)
(built: Aug 4 2017 13:04:12) ( NTS )
OS: Elementary OS 0.4.1 Loki (based on Ubuntu Xenial)
OpenSSL version: OpenSSL 1.1.0f 25 May 2017
This is what my certificate metadata looks like (actual values
replaced):
```
Bag Attributes
localKeyID: 00 11 22 33 44 55 66 77 88 99 AA BB CC DD EE FF 00 11 22
33
subject=/C=RU/ST=Moscow/O=Removed/OU=Removed/CN=Removed/emailAddress=removed@example.com
issuer=/C=RU/ST=Moscow/L=Moscow/O=Removed/OU=Removed/CN=www.example.org/emailAddress=removed@example.com
-----BEGIN CERTIFICATE-----
[certificate goes here]
```
I have reported this bug to the PPA bug tracker, and it's maintainer
requested me to report this bug here.
Original report URL: https://github.com/oerdnj/deb.sury.org/issues/661
Test script:
---------------
<?php
$address = gethostbyname('localhost');
$port = 443; // put any open port on any host here
$context = stream_context_create();
stream_context_set_option($context, 'ssl', 'capture_peer_cert', true);
stream_context_set_option($context, 'ssl', 'local_cert',
__DIR__.'/admin.crt');
stream_context_set_option($context, 'ssl', 'passphrase',
'yourCertPassword');
stream_context_set_option($context, 'ssl', 'ciphers', 'SSLv3');
stream_context_set_option($context, 'ssl', 'verify_peer', false);
stream_context_set_option($context, 'ssl', 'verify_peer_name', false);
stream_context_set_option($context, 'ssl', 'allow_self_signed', true);
$errno = null; $errstr = null;
$socket = stream_socket_client("tcp://$address:$port", $errno, $errstr,
30, STREAM_CLIENT_CONNECT, $context);
stream_socket_enable_crypto($socket, true,
STREAM_CRYPTO_METHOD_TLS_CLIENT);
Expected result:
----------------
Given that the certificate is correct, I expect no warnings to be
thrown.
Actual result:
--------------
/usr/bin/php7.1 /tmp/test.php
PHP Warning: stream_socket_enable_crypto(): Unable to set local cert
chain file `/tmp/admin.crt'; Check that your cafile/capath settings
include details of your certificate and its issuer in /tmp/test.php on
line 17
PHP Stack trace:
PHP 1. {main}() /tmp/test.php:0
PHP 2. stream_socket_enable_crypto() /tmp/test.php:17
--
Edit bug report at https://bugs.php.net/bug.php?id=75086&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75086&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75086&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75086&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75086&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75086&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75086&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75086&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75086&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75086&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75086&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75086&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75086&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75086&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75086&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75086&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75086&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75086&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75086&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75086&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75086&r=mysqlcfg