Bug #76705 [Opn->Ver]: unusable ssl => peer_fingerprint in stream_context_create()
| From: | cmb@php.net | Date: | Sun, 05 Aug 2018 13:53:46 +0000 |
| Subject: | Bug #76705 [Opn->Ver]: unusable ssl => peer_fingerprint in stream_context_create() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216609@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76705&edit=1
ID: 76705
Updated by: cmb@php.net
Reported by: test at strongsolutions dot lt
Summary: unusable ssl => peer_fingerprint in
stream_context_create()
-Status: Open
+Status: Verified
Type: Bug
Package: OpenSSL related
PHP Version: master-Git-2018-08-04 (Git)
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
I can confirm this issue and also that the attached patch would
solve it. Thanks!
> [â¦] caused by macromancy [â¦]
Gee! This[1] likely will bite us again. Shouldn't that be
refactored, Jakub?
[1] <https://github.com/php/php-src/blob/php-7.3.0beta1/ext/openssl/xp_ssl.c#L90-L95>
Previous Comments:
------------------------------------------------------------------------
[2018-08-04 15:24:27] test at strongsolutions dot lt
Description:
------------
See code.
It appears that this is caused by macromancy: value of
val is inadvertently changed by
another use of GET_VER_OPT.
https://github.com/php/php-src/blob/master/ext/openssl/xp_ssl.c#L504-L535
Test script:
---------------
file_get_contents('https://self-signed.badssl.com/', false,
stream_context_create([
'http' => [
'method' => 'GET',
],
'ssl' => [
'allow_self_signed' => true,
'peer_fingerprint' => '641450D94A65FAEB3B631028D8E86C95431DB811',
],
]));
Expected result:
----------------
Request should complete.
Actual result:
--------------
Error with message "Expected peer fingerprint must be a string or an array" is seen.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76705&edit=1