Bug #76928 [Com]: Unable to connect via TLS 1.2

From: Date: Tue, 25 Sep 2018 22:02:38 +0000
Subject: Bug #76928 [Com]: Unable to connect via TLS 1.2
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217237@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76928&edit=1

 ID:                 76928
 Comment by:         spam2 at rhsoft dot net
 Reported by:        post at rolandgruber dot de
 Summary:            Unable to connect via TLS 1.2
 Status:             Open
 Type:               Bug
 Package:            IMAP related
 Operating System:   Linux
 PHP Version:        7.2.10
 Block user comment: N
 Private report:     N

 New Comment:

be happy when it works at all and use some proxy in localhost which handles the encryption over wire

https://bugzilla.redhat.com/show_bug.cgi?id=1609777

here after upgrade to Fedora 28 the extension without even touchd it is enough that a graceful
reload leads in an endless loop of httpd crashes

sadly there is no useable replacement for my usecase testing mail servers for example if imap/pop3
deliver the same content since we had troubles of that sort in production and so tests exists with
php-imap


Previous Comments:
------------------------------------------------------------------------
[2018-09-25 21:09:16] aurelien dot grimal at tech-tips dot fr

The problem is only concerning IMAP with StartTLS (port 143) and not direct SSL on IMAPS (port 993).
So IMAP with StartTLS can't use further than TLS1.0, and IMAP on SSL can use TLS1.2.

------------------------------------------------------------------------
[2018-09-24 18:04:42] post at rolandgruber dot de

Description:
------------
It seems that the PHP IMAP module depends on some old library (libc-client2007e) that does not
support TLS v1.2. On imap_open() an error "TLS/SSL failure for <my_imap_server>: SSL
negotiation failed" is reported.

Please support recent TLS versions. This is also a security issue.

User report:

The IMAP server is running cyrus 2.5.
I had to modify the parameter tls_versions in /etc/imapd.conf from
tls_versions: tls1_2 to
tls_versions: tls1_0 tls1_1 tls1_2
to make the imapAccess work, which is less secure now.

Expected result:
----------------
IMAP connections with TLS v1.2 are working.

Actual result:
--------------
TLS/SSL failure for <my_imap_server>: SSL negotiation failed


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=76928&edit=1


Thread (7 messages)

« previous php.bugs (#217237) next »