Req #76420 [Com]: tls version change
| From: | 24d3dlct6vz5txut at brukerfeil dot eu | Date: | Wed, 06 Jun 2018 14:13:56 +0000 |
| Subject: | Req #76420 [Com]: tls version change | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215521@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76420&edit=1
ID: 76420
Comment by: 24d3dlct6vz5txut at brukerfeil dot eu
Reported by: 24dnlj6zphz at brukerfeil dot eu
Summary: tls version change
Status: Open
Type: Feature/Change Request
Package: OpenSSL related
Operating System: *
PHP Version: Next Major Version
Block user comment: N
Private report: N
New Comment:
Additional note:
Connecting to a TLS 1.2-only webserver with fsockopen works using URL ssl:// but not tls://
PHP Warning: fsockopen(): SSL operation failed with code 1. OpenSSL Error messages:
error:1409442E:SSL routines:ssl3_read_bytes:tlsv1 alert protocol version in - on line 3
PHP Warning: fsockopen(): Failed to enable crypto in - on line 3
Previous Comments:
------------------------------------------------------------------------
[2018-06-06 13:54:00] 24dnlj6zphz at brukerfeil dot eu
Description:
------------
TLS-versions prior to TLS 1.2 contain security issues and are deprecated.
All major cloud providers are now also disabling older versions
The default ssl method when not specified by client code in PHP is sslv2/3.
This opens up for security issues and also breaks tls-servers that no longer support old versions.
I suggest changing the default tls version to 1.2.
I have attached a patch, but I'm not 100% sure it is correct.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76420&edit=1