Bug #75086 [Com]: steam_socket_enable_crypto ignores verify_peer, verify_peer_name and allow_self

From: Date: Thu, 17 Aug 2017 12:48:02 +0000
Subject: Bug #75086 [Com]: steam_socket_enable_crypto ignores verify_peer, verify_peer_name and allow_self
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210709@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75086&edit=1

 ID:                 75086
 Comment by:         kelunik@php.net
 Reported by:        root dot talis at gmail dot com
 Summary:            steam_socket_enable_crypto ignores verify_peer,
                     verify_peer_name and allow_self
 Status:             Open
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Elementary OS 0.4.1 Loki
 PHP Version:        7.1.8
 Block user comment: N
 Private report:     N

 New Comment:

Uhm, why do you set stream_context_set_option($context, 'ssl', 'ciphers',
'SSLv3')?

It's pretty likely that the other side will not accept any of these, see https://www.openssl.org/docs/man1.0.2/apps/ciphers.html
for a list of ciphers that 'SSLv3' includes.

What happens if you remove that line? Might be that it's just showing the wrong error message.


Previous Comments:
------------------------------------------------------------------------
[2017-08-17 12:37:02] root dot talis at gmail dot com

Description:
------------
I try to call stream_socket_enable_crypto() on an open connection with a self-signed certificate.
verify_peer is disabled, verify_peer_name is disabled, allow_self_signed is enabled,
but PHP throws the following warning:

"stream_socket_enable_crypto(): Unable to set local cert chain file `/tmp/admin.crt';
Check that your cafile/capath settings include details of your certificate and its issuer"


PHP is installed from this repository: https://launchpad.net/~ondrej/+archive/ubuntu/php
Unfortunately, I haven't found any information about the compile configure line.
I believe that the PPA maintainer can provide this information.

My setup:
  PHP version:     PHP 7.1.8-2+ubuntu16.04.1+deb.sury.org+4 (cli)
                   (built: Aug 4 2017 13:04:12) ( NTS )
  OS:              Elementary OS 0.4.1 Loki (based on Ubuntu Xenial) 
  OpenSSL version: OpenSSL 1.1.0f 25 May 2017

This is what my certificate metadata looks like (actual values replaced):

```
Bag Attributes
    localKeyID: 00 11 22 33 44 55 66 77 88 99 AA BB CC DD EE FF 00 11 22 33 
subject=/C=RU/ST=Moscow/O=Removed/OU=Removed/CN=Removed/emailAddress=removed@example.com
issuer=/C=RU/ST=Moscow/L=Moscow/O=Removed/OU=Removed/CN=www.example.org/emailAddress=removed@example.com
-----BEGIN CERTIFICATE-----
[certificate goes here]
```

I have reported this bug to the PPA bug tracker, and it's maintainer requested me to report
this bug here.
Original report URL: https://github.com/oerdnj/deb.sury.org/issues/661

Test script:
---------------
<?php
$address = gethostbyname('localhost');
$port = 443; // put any open port on any host here

$context = stream_context_create();
stream_context_set_option($context, 'ssl', 'capture_peer_cert', true);
stream_context_set_option($context, 'ssl', 'local_cert',
__DIR__.'/admin.crt');
stream_context_set_option($context, 'ssl', 'passphrase',
'yourCertPassword');
stream_context_set_option($context, 'ssl', 'ciphers', 'SSLv3');
stream_context_set_option($context, 'ssl', 'verify_peer', false);
stream_context_set_option($context, 'ssl', 'verify_peer_name', false);
stream_context_set_option($context, 'ssl', 'allow_self_signed', true);

$errno = null; $errstr = null;
$socket = stream_socket_client("tcp://$address:$port", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, $context);

stream_socket_enable_crypto($socket, true, STREAM_CRYPTO_METHOD_TLS_CLIENT);

Expected result:
----------------
Given that the certificate is correct, I expect no warnings to be thrown.

Actual result:
--------------
/usr/bin/php7.1 /tmp/test.php
PHP Warning:  stream_socket_enable_crypto(): Unable to set local cert chain file
`/tmp/admin.crt'; Check that your cafile/capath settings include details of your certificate
and its issuer in /tmp/test.php on line 17
PHP Stack trace:
PHP   1. {main}() /tmp/test.php:0
PHP   2. stream_socket_enable_crypto() /tmp/test.php:17


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=75086&edit=1


Thread (9 messages)

« previous php.bugs (#210709) next »