Req #77505 [Opn]: streams/HTTPS cannot be used with WinSSL/schannel
| From: | ab@php.net | Date: | Fri, 25 Jan 2019 11:32:47 +0000 |
| Subject: | Req #77505 [Opn]: streams/HTTPS cannot be used with WinSSL/schannel | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-219197@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77505&edit=1
ID: 77505
Updated by: ab@php.net
Reported by: vjardin at free dot fr
Summary: streams/HTTPS cannot be used with WinSSL/schannel
Status: Open
Type: Feature/Change Request
Package: Streams related
Operating System: Windows
PHP Version: 7.3.1
Block user comment: N
Private report: N
New Comment:
Thanks for the report.
> Assuming WinSSL is used, so openssl is disabled,
There is no support for WinSSL in streams, so it can't be used. To use encrypted streams,
OpenSSL is required.
> If we enable openssl, but the certificates are into the Windows' store, then of course, it
> cannot work:
OpenSSL interacts with the Windows certificate store. The certificate store receives centralized
updates. If something is not there - most likely the store has not been updated yet. That's
also often a reason for issues with self signed certificates.
Having support for WinSSL might be a feature, yes. However, not all the dependencies support it.
Also, for the core we'd have to maintain two layers of security, which doubles efforts and bug
sources. Just depending on OpenSSL seems OK.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2019-01-23 01:35:22] vjardin at free dot fr
Description:
------------
Assuming WinSSL is used, so openssl is disabled,
$data = file_get_contents('https://www.google.fr/');
leads to
PHP Warning: file_get_contents(): Unable to find the wrapper "https" - did you forget to
enable it when you configured PHP? in ssl.php on line 2
If we enable openssl, but the certificates are into the Windows' store, then of course, it
cannot work:
$ php -d extension=openssl ssl.php
PHP Warning: file_get_contents(): SSL operation failed with code 1. OpenSSL Error messages:
error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure in ssl.php on line 7
------------------
$ php -v
PHP 7.2.14RC1 (cli) (built: Jan 6 2019 01:20:28) ( NTS MSVC15 (Visual C++ 2017) x64 )
Copyright (c) 1997-2018 The PHP Group
Zend Engine v3.2.0, Copyright (c) 1998-2018 Zend Technologies
$ php -i | findstr configu
Configure Command => cscript /nologo configure.js "--enable-snapshot-build"
"--enable-crt-debug" "--disable-zts" "--enable-pdo"
"--with-pdo-oci=C:\php-sdk\oracle\x64\instantclient_12_1\sdk,shared"
"--with-oci8=C:\php-sdk\oracle\x64\instantclient_10_2\sdk,shared"
"--with-oci8-11g=C:\php-sdk\oracle\x64\instantclient_11_2\sdk,shared"
"--with-oci8-12c=C:\php-sdk\oracle\x64\instantclient_12_1\sdk,shared"
"--enable-com-dotnet=shared" "--with-ereg=shared"
"--with-odbcver=0x0380" "--with-php-build=../win64build.vc15"
$ php -i | findstr /I SSL
SSL => Yes
SSL Version => WinSSL
core SSL => supported
extended SSL => not supported
OpenSSL support => disabled (install ext/openssl)
Test script:
---------------
ssl.php:
<?php
$data = file_get_contents('https://www.google.fr/');
var_dump($data);
Expected result:
----------------
Open a stream SSL/HTTPS connecion without OpenSSL but using WinSSL. libssh2 does support
libssh2/WinSSL. It can become the abstraction layer.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77505&edit=1