Bug #76694 [NoF]: OpenSSL don't use Windows system CA store

From: Date: Mon, 19 Nov 2018 10:27:13 +0000
Subject: Bug #76694 [NoF]: OpenSSL don't use Windows system CA store
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218040@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76694&edit=1

 ID:                 76694
 Updated by:         nikic@php.net
 Reported by:        anrdaemon at freemail dot ru
 Summary:            OpenSSL don't use Windows system CA store
 Status:             No Feedback
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Windows
 PHP Version:        5.6.37
 Block user comment: N
 Private report:     N

 New Comment:

The report was suspended because no response was provided to the questions that were asked by
@daverandom. The issue can be reopened once requested feedback is provided.


Previous Comments:
------------------------------------------------------------------------
[2018-11-19 10:09:16] anrdaemon at freemail dot ru

So, the report was suspended based on semi-educated guess? Without actual investigation?
I knew bugs.php.net tend to be like that, but not on such a scale.

------------------------------------------------------------------------
[2018-11-18 22:31:27] cmb@php.net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2018-08-02 13:53:40] daverandom@php.net

This is just a semi-educated guess, but note that a self-signed certificate will only be accepted if
the allow_self_signed context option is set, regardless of whether it exists in the trusted root CA
store. Similarly, the verify_depth context option is still respected when the system store is used.

If the problematic certificate does not fall foul of either of these factors, please check the
following:

- Are you able to load the resource in a browser that uses the system CA store, on the same client
machine, without errors?
- If you specify a cafile that contains the relevant root certificate (i.e. use the openssl verify
routine), does it work?
- Where the system store-based verify routine encounters an operational failure of some kind it will
emit an E_WARNING with a descriptive message, please ensure that you have error reporting configured
with a sufficient level and include any logged messages here.

Although there aren't currently any proper tests for this code path - something which most
certainly needs addressing - it is fairly well tested in practice, simply by real-world usage. For
example, if file_get_contents('https://packagist.org/...') didn't work out of
the box on windows then there would be frequent reports as composer would not work.

If you want to discuss directly with me further in chat, you can find in the PHP chat room on Stack
Overflow most of the time, under the screen name DaveRandom :-)

------------------------------------------------------------------------
[2018-08-02 13:01:40] anrdaemon at freemail dot ru

Description:
------------
Contrary to the release announce of PHP 5.6

- OpenSSL:
  . Fallback to Windows CA cert store for peer verification if no openssl.cafile
    ini directive or "cafile" SSL context option specified in Windows.
    (Chris Wright)

file_get_contents('https://ca.rootdir.org/');

fails with certificate verification error.

This is for all PHP versions from 5.6 to 7.2

Test script:
---------------
<?php

print file_get_contents('https://ca.rootdir.org/');


Expected result:
----------------
<html>
<body>
<h1>Hi!</h1>
<p><a href="ca.cer">Root certificate.</a></p>
</body>
</html>

Actual result:
--------------
PHP Warning:  file_get_contents(): SSL operation failed with code 1. OpenSSL Error messages:
error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed in
ssl-verify.php on line 3


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=76694&edit=1


Thread (16 messages)

« previous php.bugs (#218040) next »